Towards a UML based approach to role engineering

被引:29
作者
Epstein, P [1 ]
Sandhu, R [1 ]
机构
[1] AT&T Labs Res, Manassas, VA 20111 USA
来源
FOURTH ACM WORKSHOP ON ROLE-BASED ACCESS CONTROL, PROCEEDINGS | 1999年
关键词
role based access control; RBAC; Unified Modeling Language; UML; Role Engineering;
D O I
10.1145/319171.319184
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Role based access control (RBAC) is a promising technology for scalable access control. For RBAC to rise to its full potential, the roles must be properly constructed to reflect organizational access control policy and needs. This requires a discipline of Role Engineering to develop various components of RBAC such as role hierarchy, permissions land permission-role assignment), and constraints. The importance of Role Engineering has been recognized but very little work has been done to date. In this paper we explore the possibility of using the Unified Modeling Language (UML) to support Role Engineering. We chose UML because it is a de facto standard and reflects a consensus in the modeling community. To investigate the capability of UML for Role Engineering, we represent an existing Role framework recently published by Thomsen, O'Brien, and Bogle. This framework can be modeled in UML, with the assistance of adding a new user defined UML vocabulary.
引用
收藏
页码:135 / 143
页数:9
相关论文
共 8 条
[1]  
[Anonymous], 2000, UNIFIED MODELING LAN, DOI DOI 10.1007/3-540-40011-7_10
[2]  
BARKLEY J, 1995, P 1 ACM WORKSH ROL B
[3]  
COYNE EJ, 1995, P 1 ACM WORKSH ROL B
[4]  
LAFORE R, 1991, OBJECT ORIENTED PROG
[5]  
*RAT ROS SOFTW COR, 1996, RAT ROS CPLUSPL
[6]   Role based access control models [J].
Sandhu, RS ;
Coyne, EJ ;
Feinstein, HL ;
Youman, CE .
COMPUTER, 1996, 29 (02) :38-&
[7]  
SANDHU RS, 1998, ADV COMPUTERS, V46
[8]   Role based access control framework for network enterprises [J].
Thomsen, D ;
O'Brien, D ;
Bogle, J .
14TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 1998, :50-58