The RSL99 language for role-based separation of duty constraints

被引:43
作者
Ahn, GJ [1 ]
Sandhu, R [1 ]
机构
[1] George Mason Univ, Informat & Software Engn Dept, Lab Informat Secur Technol, Fairfax, VA 22030 USA
来源
FOURTH ACM WORKSHOP ON ROLE-BASED ACCESS CONTROL, PROCEEDINGS | 1999年
关键词
D O I
10.1145/319171.319176
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Separation of duty (SOD) is a fundamental technique for prevention of fraud and errors, known and practiced long before the existence of computers. It is discussed at several places in the literature, but there has been little work on specifying SOD policies in a systematic way. This paper describes a framework for specifying separation of duty and conflict of interest policies in role-based systems. To specify these policies, we need an appropriate language. We propose an intuitive formal language which uses system functions and sets as its basic elements. The semantics for this language is defined by its translation to a restricted form of first order predicate logic. We show how previously identified SOD properties can be expressed in our language. Moreover, we show there are other significant SOD properties which have not been previously identified in the literature. Unlike much of the previous work, this paper deals with SOD in the presence of role hierarchies. Our work shows that there are many alternate formulations of even the simplest SOD properties, with varying degree of flexibility and assurance. Our language provides us a rigorous foundation for systematic study of SOD properties.
引用
收藏
页码:43 / 54
页数:12
相关论文
共 16 条
  • [1] [Anonymous], 1999, ACM T INFORM SYSTEMS
  • [2] [Anonymous], P 1 ACM WORKSH ROL B
  • [3] [Anonymous], 1999, ACM T INFORM SYST SE
  • [4] BALDWIN RW, 1990, P IEEE S SECURITY PR, P61
  • [5] Chen F., 1995, P 1 ACM WORKSH ROL B, P39
  • [6] Clark D. D., 1987, Proceedings of the 1987 IEEE Symposium on Security and Privacy (Cat. No.87CH2416-6), P184
  • [7] Ferraiolo D. E., 1995, Proceedings. 11th Annual Computer Security Applications Conference, P241
  • [8] On the formal definition of separation-of-duty policies and their composition
    Gligor, VD
    Gavrila, SI
    Ferraiolo, D
    [J]. 1998 IEEE SYMPOSIUM ON SECURITY AND PRIVACY - PROCEEDINGS, 1998, : 172 - 183
  • [9] Kuhn DR, 1997, P 2 ACM WORKSH ROL B
  • [10] Nash M. J., 1990, Proceedings. 1990 IEEE Computer Society Symposium on Research in Security and Privacy (Cat. No.90CH2884-5), P201, DOI 10.1109/RISP.1990.63851