• DocumentCode
    3572353
  • Title

    Mutual exclusion and role inheritance affecting least privilege in RBAC

  • Author

    Habib, Muhammad Asif

  • Author_Institution
    FIM, Johannes Kepler Univ., Linz, Austria
  • fYear
    2010
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Role based access control (RBAC) always provides tight security of information and ease of management to security policy. There are certain constraints which make the information security tight. Separation of duty (SOD) in terms of mutual exclusion and role inheritance (RI) are some of those constraints which provide security of information and make the management of security policy easy. On one side after implementing separation of duty, we may able to get tight security but on the other side it can create complexity for the security administrator and the user who uses the system. In this paper we describe the complexities and complications which can be faced after implementing separation of duty in terms of mutually exclusive roles (MER). We also describe the problems which can be faced If either the role inheritance is not implemented or implemented in an incomplete manner. We also propose the solutions to the given problems and propose a model against all the problems discussed.
  • Keywords
    authorisation; MER; RBAC; information security; least privilege; mutual exclusion; mutually exclusive roles; role based access control; role inheritance; security administrator; security policy; separation of duty;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Internet Technology and Secured Transactions (ICITST), 2010 International Conference for
  • Print_ISBN
    978-1-4244-8862-9
  • Electronic_ISBN
    978-0-9564263-6-9
  • Type

    conf

  • Filename
    5678530