Task-role-based access control model

被引:130
作者
Oh, S [1 ]
Park, S [1 ]
机构
[1] Sogang Univ, Dept Comp Sci, Seoul 121742, South Korea
关键词
access control; RBAC; enterprise environment; task; role;
D O I
10.1016/S0306-4379(02)00029-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
There are many information objects and users in a large company. It is an important issue how to control user's access in order that only authorized user can access information objects. Traditional access control models-discretionary access control, mandatory access control, and role-based access control-do not properly reflect the characteristics of enterprise environment. This paper proposes an improved access control model for enterprise environment. The characteristics of access control in an enterprise environment are examined and a task-role-based access control (T-RBAC) model founded on concept of classification of tasks is introduced. Task is a fundamental unit of business work or business activity. T-RBAC deals with each task differently according to its class, and supports task level access control and supervision role hierarchy. T-RBAC is a suitable access control model for industrial companies. (C) 2002 Elsevier Science Ltd. All rights reserved.
引用
收藏
页码:533 / 562
页数:30
相关论文
共 27 条
  • [1] AHN GH, 1999, P 4 ACM WORKSH ROL B
  • [2] ALSALQAN Y, 1999, P IEEE 8 INT WORKSH
  • [3] AMOROSO EG, 1994, FUNDAMENTAL COMPUTER
  • [4] [Anonymous], 1995, INTRO DATABASE SYSTE
  • [5] BARKA E, 2000, P 14 ANN COMP SEC AP
  • [6] Dagstull GC, 1994, ACM EUR SIGOPS WORKS
  • [7] FERRAIO D, 1995, P 11 ANN COMP SEC AP, P12
  • [8] GAVRILA SI, 1998, P 3 ACM WORKSH ROL B
  • [9] HERRMANN G, 1998, P 31 HAW INT C SYST
  • [10] JAEGER T, 1999, P 4 ACM WORKSH ROL B