Towards Session-aware RBAC Administration and Enforcement with XACML

被引:4
|
作者
Xu, Min [1 ]
Wijesekera, Duminda [1 ]
Zhang, Xinwen [2 ]
Cooray, Deshan [1 ]
机构
[1] George Mason Univ, Dept Comp Sci, Fairfax, VA 22030 USA
[2] Samsung Informat Syst Amer, Comp Sci Lab, San Jose, CA USA
关键词
D O I
10.1109/POLICY.2009.27
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
An administrative role-based access control (ARBAC) model specifies administrative policies over a role-based access control (RBAC) system, where an administrative permission may change an RBAC policy by updating permissions assigned to roles, or assigning/revoking users to/from roles. Consequently, enforcing ARBAC policies over an active access controller while some users are using protected resources would result in conflicts: a policy may be in effect in the RBAC system while being updated by an ARBAC operation. Towards solving this concurrency problem, we propose a session-aware administrative model for RBAC. We show how the concurrency problem can be resolved by enhancing the eXtensible Access Control Markup Language (XACML) reference implementation. In order to do so, we develop an XACML-ARBAC profile to specify ARBAC policies, and enforce these polices by building an ARBAC enforcement module and a session administrative module. The former synchronizes with the evaluation of access control requests. The latter revokes conflicting ongoing user sessions immediately prior to enforcing administrative operations. Experimental studies show reasonable performance characteristics of our initial enhancement to Sun's reference implementation.
引用
收藏
页码:9 / +
页数:2
相关论文
共 50 条
  • [1] Neural Session-Aware Recommendation
    Tu Minh Phuong
    Tran Cong Thanh
    Ngo Xuan Bach
    IEEE ACCESS, 2019, 7 : 86884 - 86896
  • [2] Runtime Administration of an RBAC Profile for XACML
    Xu, Min
    Wijesekera, Duminda
    Zhang, Xinwen
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2011, 4 (04) : 286 - 299
  • [3] Session-Aware Clinical Information Systems
    Nytro, Oystein
    Sorby, Inger Dybdahl
    Alsos, Ole A.
    BUSINESS PROCESS MANAGEMENT WORKSHOPS, 2009, 17 : 397 - 407
  • [4] SessionStore: A Session-Aware Datastore for the Edge
    Mortazavi, Seyed Hossein
    Salehe, Mohammad
    Balasubramanian, Bharath
    de Lara, Eyal
    PuzhavakathNarayanan, Shankaranarayanan
    4TH IEEE INTERNATIONAL CONFERENCE ON FOG AND EDGE COMPUTING (ICFEC 2020), 2020, : 59 - 68
  • [5] SSL/TLS session-aware user authentication
    Oppliger, Rolf
    Hauser, Ralf
    Basin, David
    COMPUTER, 2008, 41 (03) : 59 - +
  • [6] A Joint Neural Network for Session-Aware Recommendation
    Guo, Yupu
    Zhang, Duolong
    Ling, Yanxiang
    Chen, Honghui
    IEEE ACCESS, 2020, 8 (08): : 74205 - 74215
  • [7] SSL/TLS session-aware user authentication revisited
    Oppliger, Rolf
    Hauser, Ralf
    Basin, David
    COMPUTERS & SECURITY, 2008, 27 (3-4) : 66 - 70
  • [8] Exploiting Session Information in BERT-based Session-aware Sequential Recommendation
    Seol, Jinseok Jamie
    Ko, Youngrok
    Lee, Sang-goo
    PROCEEDINGS OF THE 45TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL (SIGIR '22), 2022, : 2639 - 2644
  • [9] A sentiment-guided session-aware recommender system
    Khurana, Purnima
    Gupta, Bhavna
    Sharma, Ravish
    Bedi, Punam
    JOURNAL OF SUPERCOMPUTING, 2024, 80 (19): : 27204 - 27243
  • [10] Hybrid session-aware recommendation with feature-based models
    Bauer, Josef
    Jannach, Dietmar
    USER MODELING AND USER-ADAPTED INTERACTION, 2024, 34 (03) : 691 - 728