General Attribute Based RBAC Model for Web Services

被引:3
作者
ZHU Yiqun LI Jianhua ZHANG Quanhai Department of Electronic Engineering Shanghai Jiao Tong University Shanghai China [200030 ]
机构
关键词
attribute; rule; user-role assignment; role-based access control (RBAC); access policy;
D O I
暂无
中图分类号
TP393.09 [];
学科分类号
080402 ;
摘要
Growing numbers of users and many access policies that involve many different resource attributes in service-oriented environments cause various problems in protecting resource. This paper analyzes the relationships of resource attributes to user at- tributes based on access policies for Web services, and proposes a general attribute based role-based access control(GARBAC) model. The model introduces the notions of single attribute ex- pression, composite attribute expression, and composition permis- sion, defines a set of elements and relations among its elements and makes a set of rules, assigns roles to user by inputing user’s attributes values. The model is a general access control model, can support more granularity resource information and rich access control policies, also can be used to wider application for services. The paper also describes how to use the GARBAC model in Web services environments.
引用
收藏
页码:81 / 86
页数:6
相关论文
共 4 条
[1]   A dynamic context-aware access control architecture for e-services [J].
Kapsalis, Vassilis ;
Hadellis, Loukas ;
Karelis, Dimitris ;
Koubias, Stavros .
COMPUTERS & SECURITY, 2006, 25 (07) :507-521
[2]  
Proposed NIST standard for role-based access control[J] . David F. Ferraiolo,Ravi Sandhu,Serban Gavrila,D. Richard Kuhn,Ramaswamy Chandramouli.ACM Transactions on Information and System Security (TISSEC) . 2001 (3)
[3]  
Rule-Based RBAC with Negative Authorization. Mohammad A,Al-Kahtani H,Ravi S. Proceedings of the 20th Annual Computer Security Applications Conference (ACSAC‘04) . 2004
[4]  
An Attribute and Role Based Access Control Model for Web Services. Liu Miao,Guo Heqing,Su Jindian. Proceedings of the Fourth International Conference on Machine Learning and Cybernetics . 2005