On the formal definition of separation-of-duty policies and their composition

被引:73
作者
Gligor, VD [1 ]
Gavrila, SI [1 ]
Ferraiolo, D [1 ]
机构
[1] Univ Maryland, Dept Elect Engn, College Pk, MD 20742 USA
来源
1998 IEEE SYMPOSIUM ON SECURITY AND PRIVACY - PROCEEDINGS | 1998年
关键词
D O I
10.1109/SECPRI.1998.674833
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper we define formally a wide variety of separation-of-duty (SoD) properties, which include the best known to date, and establish their relationships within a formal model of role-based access control (RBAC). The formalism helps remove all ambiguities of informal definition, and offers a,wide choice of implementation strategies. We also explore the composability of SoD properties and policies under a simple criterion. We conclude that practical implementation for SoD policies requires new method's and tools for security administration even within applications that already, support RBAC, such as most database management systems.
引用
收藏
页码:172 / 183
页数:12
相关论文
empty
未找到相关数据