Integrating Delegation with the Formal Core RBAC Model

被引:1
|
作者
Abdallah, Ali E. [1 ]
Takabi, Hassan [1 ]
机构
[1] London S Bank Univ, ESecur Res Ctr, London SE1 0AA, England
关键词
D O I
10.1109/IAS.2008.66
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Role-based access control (RBAC) models are a powerful tool for describing and managing authorization, particularly, in large organizations. The benefits of using formal methods to describe RBAC models in a clear, consistent and rigorous manner have been recognized. Notable exemplars, that have been formulated in the formal specification notation Z, include NIST's reference RBAC model and the minimalist Core RBAC model. These models, however, do not support delegation, an important authorization feature which is often deployed in real access control systems. In RBAC, delegation empowers a user in a certain role to authorize another user to perform the tasks permissible to that role. This paper aims at integrating a version of role delegation, known as grant independent delegation, with the Core RBAC model. The paper introduces a state based model in which grant independent delegation and revocation operations are formally specified in Z. Integration with the Core RBAC model is achieved by simply combining the two models using the standard Z schema conjunction operator.
引用
收藏
页码:33 / 36
页数:4
相关论文
共 50 条
  • [41] Delegation: A Core Leadership Skill
    Baker, Edward L.
    Murphy, Susan A.
    JOURNAL OF PUBLIC HEALTH MANAGEMENT AND PRACTICE, 2022, 28 (04): : 430 - 432
  • [42] A Valid and Correct-by-Construction Formal Specification of RBAC
    Gadouche, Hania
    Farah, Zoubeyr
    Tari, Abdelkamel
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2020, 14 (02) : 41 - 61
  • [43] Delegation of Medical Services - Medical Core competence and Delegation in Surgery
    Meyer, H. C. Hans-Joachim
    ZENTRALBLATT FUR CHIRURGIE, 2017, 142 (03): : 239 - 240
  • [44] RBAC-based Delegation Authorization with Trust Computing and Collaborative Security Strategy
    Sun, Wei
    International Journal of Network Security, 2023, 25 (04) : 666 - 679
  • [45] Integrating Formal Model Checking with the RTEdge (TM) AADL Microkernel
    Gheorghe, Serban
    SAE INTERNATIONAL JOURNAL OF AEROSPACE, 2011, 4 (02): : 762 - 778
  • [46] RBAC model for SCADA
    Majdalawieh, Munir
    Parisi-Presicce, Francesco
    Sandhu, Ravi
    INNOVATIVE ALGORITHMS AND TECHNIQUES IN AUTOMATION, INDUSTRIAL ELECTRONICS AND TELECOMMUNICATIONS, 2007, : 329 - +
  • [47] A formal object specification technique integrating object and functional model
    Wagner, A
    INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 1997, 7 (04) : 503 - 524
  • [48] SH-CRBAC: Integrating Attribute and Status Constraints into the RBAC Model in Smart Home Systems
    Zou, Deqing
    Park, Jong Hyuk
    Kim, Tai-Hoon
    Chen, Xueguang
    COMPUTER JOURNAL, 2009, 52 (08): : 861 - 870
  • [49] A Flexible Authorization Delegation Method in Multi-domain Environments Employing RBAC Policies
    Liao, Junguo
    Yang, Feng
    Zhang, Huifu
    Zhu, Gengming
    Zhu, Bin
    DCABES 2008 PROCEEDINGS, VOLS I AND II, 2008, : 1142 - 1147
  • [50] A Formal Framework to Elicit Roles with Business Meaning in RBAC Systems
    Colantonio, Alessandro
    Di Pietro, Roberto
    Ocello, Alberto
    Verde, Nino Vincenzo
    SACMAT'09: PROCEEDINGS OF THE 14TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2009, : 85 - 94