Integrating Delegation with the Formal Core RBAC Model

被引:1
|
作者
Abdallah, Ali E. [1 ]
Takabi, Hassan [1 ]
机构
[1] London S Bank Univ, ESecur Res Ctr, London SE1 0AA, England
关键词
D O I
10.1109/IAS.2008.66
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Role-based access control (RBAC) models are a powerful tool for describing and managing authorization, particularly, in large organizations. The benefits of using formal methods to describe RBAC models in a clear, consistent and rigorous manner have been recognized. Notable exemplars, that have been formulated in the formal specification notation Z, include NIST's reference RBAC model and the minimalist Core RBAC model. These models, however, do not support delegation, an important authorization feature which is often deployed in real access control systems. In RBAC, delegation empowers a user in a certain role to authorize another user to perform the tasks permissible to that role. This paper aims at integrating a version of role delegation, known as grant independent delegation, with the Core RBAC model. The paper introduces a state based model in which grant independent delegation and revocation operations are formally specified in Z. Integration with the Core RBAC model is achieved by simply combining the two models using the standard Z schema conjunction operator.
引用
收藏
页码:33 / 36
页数:4
相关论文
共 50 条
  • [1] DW-RBAC: A formal security model of delegation and revocation in workflow systems
    Wainer, Jacques
    Kumar, Akhil
    Barthelmess, Paulo
    INFORMATION SYSTEMS, 2007, 32 (03) : 365 - 384
  • [2] A delegation model for extended RBAC
    Meriam Ben-Ghorbel-Talbi
    Frédéric Cuppens
    Nora Cuppens-Boulahia
    Adel Bouhoula
    International Journal of Information Security, 2010, 9 : 209 - 236
  • [3] A delegation model for extended RBAC
    Ben-Ghorbel-Talbi, Meriam
    Cuppens, Frederic
    Cuppens-Boulahia, Nora
    Bouhoula, Adel
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2010, 9 (03) : 209 - 236
  • [4] An Extended Delegation Model Based On RBAC
    Li, Jinshuang
    Chang, Guiran
    2008 INTERNATIONAL WORKSHOP ON INFORMATION TECHNOLOGY AND SECURITY, 2008, : 228 - 231
  • [5] ABDM: An extended flexible delegation model in RBAC
    Li, Min
    Wang, Hua
    2008 IEEE 8TH INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY, VOLS 1 AND 2, 2008, : 390 - 395
  • [6] Capability-Based Delegation Model in RBAC
    Hasebe, Koji
    Mabuchi, Mitsuhiro
    Matsushita, Akira
    SACMAT 2010: PROCEEDINGS OF THE 15TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2010, : 109 - 118
  • [7] A New Research of Delegation Agent Model Based On RBAC
    Zhang, Ping
    Shi, Nian-Feng
    Jiang, Hong
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATION AND SENSOR NETWORKS (WCSN 2016), 2016, 44 : 15 - 18
  • [8] Timing constraints-based RBAC delegation model
    Co-soft R and D Center, Sun Yat-sen University, Guangzhou 510275, China
    不详
    Jisuanji Jicheng Zhizao Xitong, 2008, 8 (1533-1538):
  • [9] An Extended RBAC Model for Task Delegation in Workflow Systems
    Gaaloul, Khaled
    Proper, Erik
    Charoy, Francois
    WORKSHOPS ON BUSINESS INFORMATICS RESEARCH, 2012, 106 : 51 - +
  • [10] A formal proximity model for RBAC systems
    Gupta, Aditi
    Kirkpatrick, Michael S.
    Bertino, Elisa
    COMPUTERS & SECURITY, 2014, 41 : 52 - 67