A History-based Constraint for Separation-of-Duty Policy in Role Based Access Control Model

被引:0
|
作者
Wang, Duoqiang [1 ]
Liu, Wengfang [1 ]
Lu, Jianfeng [1 ]
Ma, Xiaopu [1 ]
机构
[1] Huazhong Univ Sci & Technol, Coll Comp Sci & Technol, Wuhan 430074, Peoples R China
关键词
role based access control; separation-of-duty; history-based constraint; statically mutually exclusive roles;
D O I
暂无
中图分类号
F [经济];
学科分类号
02 ;
摘要
Separation-of-duty (SoD) is widely considered to be a fundamental principle in computer security. Role-based access control (RBAC) is today's dominant access control model, and supporting SoD policy is widely regarded as one of RBAC's main strengths. In this paper, we show that checking whether a RBAC state satisfies a given static SoD (SSoD) policy is a coNP-complete problem, and using statically mutually exclusive roles (SHIER) to enforce SSoD is usually computationally expensive, while enforcing SSoD policies by a history-based constraint is practicable. Our approach is focused on high-level SSoD policy, and the key idea is to record each permission access request, this history is maintained and processed by two different mechanisms based on two cases, one case is n=2 or m=n, the other case is 2<n<m, The history-based constraint consists of the two cases addresses the goal of the high-level SSoD policy in RBAC model.
引用
收藏
页码:195 / 199
页数:5
相关论文
共 50 条
  • [1] History-based Constraints for Dynamic Separation-of-Duty Policies in Usage Control
    Lu, Jianfeng
    Xu, Dewu
    2011 INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT), VOLS 1-4, 2012, : 2438 - 2442
  • [2] Policy-Engineering Optimization with Visual Representation and Separation-of-Duty Constraints in Attribute-Based Access Control
    Sun, Wei
    Su, Hui
    Xie, Huacheng
    FUTURE INTERNET, 2020, 12 (10): : 1 - 28
  • [3] Specification and Enforcement of Separation-of-Duty Policies in Role-base Access Control
    Lu, Jianfeng
    Zhou, Jiaqing
    2011 INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT), VOLS 1-4, 2012, : 2135 - 2140
  • [4] Analysis of enhanced separation of duty in role-based access control model
    Zhang, ZK
    Geng, YP
    Li, TY
    Xiao, JG
    Proceedings of the 11th Joint International Computer Conference, 2005, : 69 - 72
  • [5] HBAC: A model for history-based access control and its model checking
    Wang, Jing
    Takata, Yoshiaki
    Seki, Hiroyuki
    COMPUTER SECURITY - ESORICS 2006, PROCEEDINGS, 2006, 4189 : 263 - +
  • [6] Permission-Based Separation of Duty in Dynamic Role-Based Access Control Model
    Aftab, Muhammad Umar
    Qin, Zhiguang
    Hundera, Negalign Wake
    Ariyo, Oluwasanmi
    Zakria
    Ngo Tung Son
    Dinh, Tran Van
    SYMMETRY-BASEL, 2019, 11 (05):
  • [7] History-based access control with local policies
    Bartoletti, M
    Degano, P
    Ferrari, GL
    FOUNDATIONS OF SOFTWARE SCIENCE AND COMPUTATION STRUCTURES, PROCEEDINGS, 2005, 3441 : 316 - 332
  • [8] History-based access control for distributed processes
    Martins, F
    Vasconcelos, V
    TRUSTWORTHY GLOBAL COMPUTING, 2005, 3705 : 98 - 115
  • [9] History-based access control and secure information flow
    Banerjee, A
    Naumann, DA
    CONSTRUCTION AND ANALYSIS OF SAFE, SECURE, AND INTEROPERABLE SMART DEVICES, 2005, 3362 : 27 - 48
  • [10] Separation of Duty Constraint for Permission Based Delegation Model
    Huang, Chao
    Sun, Jianling
    Wang, Xinyu
    Si, Yuanjie
    ISBIM: 2008 INTERNATIONAL SEMINAR ON BUSINESS AND INFORMATION MANAGEMENT, VOL 1, 2009, : 465 - 468