Role based access control design using three-way formal concept analysis

被引:23
作者
Subramanian, Chandra Mouliswaran [1 ]
Cherukuri, Aswani Kumar [1 ]
Chelliah, Chandrasekar [2 ]
机构
[1] Vellore Inst Technol, Sch Informat Technol & Engn, Vellore 632014, Tamil Nadu, India
[2] Periyar Univ, Dept Comp Sci, Salem 636011, Tamil Nadu, India
关键词
Access control; Role based access control; 3WCA; Three-way concept; Three-way concept lattice; APPROXIMATE CONCEPT CONSTRUCTION; CONTROL MODELS; KNOWLEDGE REDUCTION; DECISION CONTEXTS; POLICIES;
D O I
10.1007/s13042-018-0840-7
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Role based access control (RBAC) is one of the popular access control models. On representing the policy behind RBAC, the literatures investigate the use of various knowledge representation techniques such as Descriptive logics, Formal Concept Analysis (FCA), Ontology etc. Based on the input of binary access control table, the existing knowledge representation techniques on RBAC derives two-way decisions whether to permit the access request or not. It works well when single element in the set of elements of a constituent of RBAC initiates the access request. Consider the scenario of multiple distinct elements in the set of elements of a constituent of RBAC initiate the collective access request to a set of elements in other constituent of RBAC. In many cases of this scenario, some elements possess but not all of the elements possess the permission to access all elements in other subset of a constituent of RBAC. On this situation, the collective access decision to those multiple distinct elements in the set of elements of a RBAC constituent appears in three forms such as permit, deny and non-commitment. Three-way formal concept analysis (3WCA) is an emerging knowledge representation technique which provides two types of three-way concepts and their lattices to enable three-way decisions from the binary information table. At this juncture, it is more suitable to apply 3WCA on representing the RBAC policy to enable three-way decisions instead of existing two-way decisions in classical FCA and triadic FCA. The main objective of this paper is to propose a methodology for modelling RBAC using 3WCA and attain its distinctive merits. Our discussion is on two lines of inquiry. We present on how 3WCA can provide suitable representation of RBAC policy and whether this representation follows role hierarchy and constraints of RBAC.
引用
收藏
页码:1807 / 1837
页数:31
相关论文
共 54 条
[1]  
[Anonymous], 2012, FORMAL CONCEPT ANAL
[2]  
[Anonymous], 2001, LNCS, DOI DOI 10.1007/3-540-45608-23
[3]  
[Anonymous], THESIS
[4]   A comprehensive modeling framework for role-based access control policies [J].
Ben Fadhel, Ameni ;
Bianculli, Domenico ;
Briand, Lionel .
JOURNAL OF SYSTEMS AND SOFTWARE, 2015, 107 :110-126
[5]  
Chae JH, 2007, LECT NOTES COMPUT SC, V4705, P500
[6]  
Chen L, 2007, SACMAT'07: PROCEEDINGS OF THE 12TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, P157
[7]   Ontology-based access control model for security policy reasoning in cloud computing [J].
Choi, Chang ;
Choi, Junho ;
Kim, Pankoo .
JOURNAL OF SUPERCOMPUTING, 2014, 67 (03) :711-722
[8]   ABAC and RBAC: Scalable, Flexible, and Auditable Access Management [J].
Coyne, Ed ;
Weil, Timothy R. .
IT PROFESSIONAL, 2013, 15 (03) :14-16
[9]  
Dau F, 2009, LECT NOTES ARTIF INT, V5662, P141, DOI 10.1007/978-3-642-03079-6_11
[10]  
Ferraiolo D. F., 2001, ACM Transactions on Information and Systems Security, V4, P224, DOI 10.1145/501978.501980