A model for attribute-based user-role assignment

被引:86
作者
Al-Kahtani, MA [1 ]
Sandhu, R [1 ]
机构
[1] George Mason Univ, Fairfax, VA 22030 USA
来源
18TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS | 2002年
关键词
D O I
10.1109/CSAC.2002.1176307
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Role-Based Access Control (RBAC) model is traditionally used to manually assign users to appropriate roles, based on a specific enterprise policy, thereby authorizing them to use the roles' permissions. In environments where the service-providing enterprise has a huge customer base this task becomes formidable. An appealing solution is to automatically assign users to roles. The central contribution of this paper is to describe a model to dynamically assign users to roles based on a finite set of rules defined by the enterprise. These rules take into consideration the attributes of users and any constraints set forth by the enterprise's security policy. The model also allows dynamic revocation of assigned roles based on conditions specified in the security policy. The model provides a language to express these rules and defines a mechanism to determine seniority among different rules. The paper also, shows how to use the model to express Mandatory Access Controls (MAC).
引用
收藏
页码:353 / 362
页数:10
相关论文
共 9 条
[1]  
HERZBERG A, 2000, P 2000 IEEE S SEC PR
[2]  
Osborn S., 2000, ACM Transactions on Information and Systems Security, V3, P85, DOI 10.1145/354876.354878
[3]  
PARK J, 2001, ACM T INFORMATION SY, V4
[4]  
SANDHU R., 1999, ACM T INFORM SYST SE, V2, P105, DOI 10.1145/300830.300839
[5]  
SANDHU R, 1996, IEEE COMPUTER, V29
[6]  
YAO W, 2001, SACMAT 01 CHANT VIRG
[7]  
Zhong Y., 2001, IEEE WORKSH SEC DIST
[8]  
2001, DYNAMIC GROUPS LDAPV
[9]  
1997, RFC2251