Integrating Delegation with the Formal Core RBAC Model

被引:1
|
作者
Abdallah, Ali E. [1 ]
Takabi, Hassan [1 ]
机构
[1] London S Bank Univ, ESecur Res Ctr, London SE1 0AA, England
关键词
D O I
10.1109/IAS.2008.66
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Role-based access control (RBAC) models are a powerful tool for describing and managing authorization, particularly, in large organizations. The benefits of using formal methods to describe RBAC models in a clear, consistent and rigorous manner have been recognized. Notable exemplars, that have been formulated in the formal specification notation Z, include NIST's reference RBAC model and the minimalist Core RBAC model. These models, however, do not support delegation, an important authorization feature which is often deployed in real access control systems. In RBAC, delegation empowers a user in a certain role to authorize another user to perform the tasks permissible to that role. This paper aims at integrating a version of role delegation, known as grant independent delegation, with the Core RBAC model. The paper introduces a state based model in which grant independent delegation and revocation operations are formally specified in Z. Integration with the Core RBAC model is achieved by simply combining the two models using the standard Z schema conjunction operator.
引用
收藏
页码:33 / 36
页数:4
相关论文
共 50 条
  • [21] Formal Verification of Liferay RBAC
    Calzavara, Stefano
    Rabitti, Alvise
    Bugliesi, Michele
    ENGINEERING SECURE SOFTWARE AND SYSTEMS (ESSOS 2015), 2015, 8978 : 1 - 16
  • [22] An access control model of workflow system integrating RBAC and TBAC
    Zhou, Xiangning
    Wang, Zhaolong
    INTEGRATION AND INNOVATION ORIENT TO E-SOCIETY, VOL 2, 2007, 252 : 246 - +
  • [23] An access control model of workflow system integrating RBAC and TBAC
    School of Information and Electronic Engineering, ShanDong Institute of Business and Technology, Yantai
    264005, China
    不详
    264005, China
    IFIP Advances in Information and Communication Technology, 2007, (246-251)
  • [24] The Design of Visual RBAC Model Based on UML and XACML Integrating
    Fan, Baode
    Li, Mengmeng
    PROCEEDINGS OF INTERNATIONAL CONFERENCE ON SOFT COMPUTING TECHNIQUES AND ENGINEERING APPLICATION, ICSCTEA 2013, 2014, 250 : 213 - 222
  • [25] A formal model for integrating multiple views
    Bowles, J. K. F.
    Bordbar, B.
    SEVENTH INTERNATIONAL CONFERENCE ON APPLICATION OF CONCURRENCY TO SYSTEM DESIGN, PROCEEDINGS, 2007, : 71 - +
  • [26] Cellular Automata based role-delegation in RBAC
    Jeon, Jun-Cheol
    Yoo, Kee-Young
    CELLULAR AUTOMATA, PROCEEDINGS, 2006, 4173 : 588 - 594
  • [27] On the formal verification of delegation in SESAME
    Ayadi, MM
    Bolignano, D
    COMPASS '97 - ARE WE MAKING PROGRESS TOWARDS COMPUTER ASSURANCE?, 1997, : 23 - 34
  • [28] A Formal Model for Integrating Consent Management Into MLOps
    Peyrone, Neda
    Wichadakul, Duangdao
    IEEE ACCESS, 2024, 12 : 142524 - 142541
  • [29] Integrating Delegation Into the Undergraduate Curriculum
    Saccomano, Scott J.
    Zipp, Genevieve Pinto
    CREATIVE NURSING, 2014, 20 (02) : 106 - 115
  • [30] Integrating RBAC, MIC, and MLS in Verified Hierarchical Security Model for Operating System
    Devyanin, P. N.
    Khoroshilov, A., V
    Kuliamin, V. V.
    Petrenko, A. K.
    Shchepetkov, I., V
    PROGRAMMING AND COMPUTER SOFTWARE, 2020, 46 (07) : 443 - 453