• DocumentCode
    3366332
  • Title

    Enhancing Role-Based Access Control Model through Fuzzy Relations

  • Author

    Takabi, Hassan ; Amini, Morteza ; Jalili, Rasool

  • Author_Institution
    Sharif Univ. of Technol., Tehran
  • fYear
    2007
  • fDate
    29-31 Aug. 2007
  • Firstpage
    131
  • Lastpage
    136
  • Abstract
    Role-Based Access Control (RBAC) model is naturally suitable to organizations where users are assigned organizational roles with well-defined privileges. However, due to the large number of users in nowadays online services of organizations and enterprises, assigning users to roles is a tiresome task and maintaining user-role assignment up- to-date is costly and error-prone. Additionally, with the increasing number of users, RBAC may have problems in prohibiting cheat and changing roles of users. In order to categorize information and formulate security policies, human decision making is required which is naturally fuzzy in the real world. This leads using a fuzzy approach to address the issue in order to provide a more practical solution. In this paper, applicability of fuzzy set theory to RBAC has been investigated by identifying access control building blocks which are fuzzy in essence. An existing RBAC model is extended to allow imprecise access control policies, using the concept of trustworthiness which is fuzzy in nature. We call the extended model as Fuzzy RBAC. Applicability of the extended model has been evaluated through some case studies.
  • Keywords
    authorisation; decision making; fuzzy set theory; fuzzy relation approach; fuzzy set theory; human decision making; role-based access control model; Access control; Companies; Computer networks; Computer security; Fuzzy control; Fuzzy set theory; Information security; Information technology; Insurance; Permission;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance and Security, 2007. IAS 2007. Third International Symposium on
  • Conference_Location
    Manchester
  • Print_ISBN
    0-7695-2876-7
  • Electronic_ISBN
    978-0-7695-2876-2
  • Type

    conf

  • DOI
    10.1109/IAS.2007.69
  • Filename
    4299763