Task-constrained RBAC model and its Privilege Redundancy Analysis

被引:0
作者
Zhou, Yanjie [1 ]
Ma, Li [1 ]
Wen, Min [2 ]
机构
[1] Jiangxi Sci & Technol Normal Univ, Coll Math & Comp Sci, Nanchang, Peoples R China
[2] Nanchang Inst Technol, Dept Civil & Architectural Engn, Nanchang, Peoples R China
来源
2015 2ND INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND CONTROL ENGINEERING ICISCE 2015 | 2015年
关键词
Access control; RBAC; Task; Role; ACCESS-CONTROL; ANSI STANDARD; CRITIQUE;
D O I
10.1109/ICISCE.2015.113
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
RBAC supports the principle of least privilege by the appropriate combination of roles assigned to users. However, the minimum role set is hard to find. Role hierarchy and inheritance can result in aggregating lots of permissions. To solve this problem, a task-constrained RBAC model is proposed in this paper, which presents four task-constraint rules to restrict the permission inheritance and role activation. An approach to calculate the redundancy of permissions is represented also, which can be used to compare the different opinion on whether single role activation can get less privilege or multiple role activation can.
引用
收藏
页码:489 / 492
页数:4
相关论文
共 11 条
[1]  
[Anonymous], 2004, 3592004 ANSI INCITS
[2]  
Byuens K., 2011, SOFTWARE SYSTEM MODE
[3]  
Deng Ji-Bo, 2003, Journal of Software, V14, P76
[4]  
Dong L.J., 2012, J SOFTWARE, V7, P398
[5]   RBAC standard rationale - Comments on "A Critique of the ANSI Standard on Role-Based Access Control" [J].
Ferraiolo, David ;
Kuhn, Rick ;
Sandhu, Ravi .
IEEE SECURITY & PRIVACY, 2007, 5 (06) :51-53
[6]   A critique of the ANSI standard on role-based access control [J].
Li, Ninghui ;
Byun, Ji-Won ;
Bertino, Elisa .
IEEE SECURITY & PRIVACY, 2007, 5 (06) :41-49
[7]  
Liu Wei, 2009, Journal of Software, V20, P1048, DOI 10.3724/SP.J.1001.2009.03261
[8]   Task-role-based access control model [J].
Oh, S ;
Park, S .
INFORMATION SYSTEMS, 2003, 28 (06) :533-562
[9]   PROTECTION OF INFORMATION IN COMPUTER SYSTEMS [J].
SALTZER, JH ;
SCHROEDER, MD .
PROCEEDINGS OF THE IEEE, 1975, 63 (09) :1278-1308
[10]  
Sandhu R., 2008, P 3 INT C AV REL SEC