A History-based Constraint for Separation-of-Duty Policy in Role Based Access Control Model

被引:0
|
作者
Wang, Duoqiang [1 ]
Liu, Wengfang [1 ]
Lu, Jianfeng [1 ]
Ma, Xiaopu [1 ]
机构
[1] Huazhong Univ Sci & Technol, Coll Comp Sci & Technol, Wuhan 430074, Peoples R China
关键词
role based access control; separation-of-duty; history-based constraint; statically mutually exclusive roles;
D O I
暂无
中图分类号
F [经济];
学科分类号
02 ;
摘要
Separation-of-duty (SoD) is widely considered to be a fundamental principle in computer security. Role-based access control (RBAC) is today's dominant access control model, and supporting SoD policy is widely regarded as one of RBAC's main strengths. In this paper, we show that checking whether a RBAC state satisfies a given static SoD (SSoD) policy is a coNP-complete problem, and using statically mutually exclusive roles (SHIER) to enforce SSoD is usually computationally expensive, while enforcing SSoD policies by a history-based constraint is practicable. Our approach is focused on high-level SSoD policy, and the key idea is to record each permission access request, this history is maintained and processed by two different mechanisms based on two cases, one case is n=2 or m=n, the other case is 2<n<m, The history-based constraint consists of the two cases addresses the goal of the high-level SSoD policy in RBAC model.
引用
收藏
页码:195 / 199
页数:5
相关论文
共 50 条
  • [11] A history-based model of the enhanced Chinese Wall policy
    Zhao, QS
    Sun, YF
    Liang, HL
    Zhang, XF
    Sun, B
    Bi, XD
    CHINESE JOURNAL OF ELECTRONICS, 2002, 11 (04): : 439 - 443
  • [12] Minimum User Requirement in Role Based Access Control with Separation of Duty Constraints
    Roy, Arindam
    Sural, Shamik
    Majumdar, Arun Kumar
    2012 12TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS DESIGN AND APPLICATIONS (ISDA), 2012, : 386 - 391
  • [13] A logical framework for history-based access control and reputation systems
    Krukow, Karl
    Nielsen, Mogens
    Sassone, Vladimiro
    JOURNAL OF COMPUTER SECURITY, 2008, 16 (01) : 63 - 101
  • [14] Reliability of separation of duty in ANSI standard role-based access control
    Esna-Ashari, M.
    Rabiee, H. R.
    Mirian-Hosseinabadi, S. H.
    SCIENTIA IRANICA, 2011, 18 (06) : 1416 - 1424
  • [15] Efficient IRM enforcement of history-based access control policies
    Yan, Fei
    Fong, Philip W. L.
    Proceedings of the 4th International Symposium on ACM Symposium on Information, Computer and Communications Security, ASIACCS'09, 2009, : 35 - 46
  • [16] Permission Based Implementation of Dynamic Separation of Duty (DSD) in Role Based Access Control (RBAC)
    Habib, Muhammad Asif
    Mahmood, Nasir
    Shahid, Muhammad
    Aftab, Muhammad Umar
    Ahmad, Uzair
    Faisal, Ch. Muhammad Nadeem
    2014 8TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND COMMUNICATION SYSTEMS (ICSPCS), 2014,
  • [17] A system architecture for history-based access control for XML documents
    Roeder, Patrick
    Tafreschi, Omid
    Mellgren, Fredrik
    Eckert, Claudia
    INFORMATION AND COMMUNICATIONS SECURITY, PROCEEDINGS, 2007, 4681 : 362 - 374
  • [18] A scalable history-based policy engine
    Gama, Pedro
    Ribeiro, Carlos
    Ferreira, Paulo
    SEVENTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2006, : 100 - +
  • [19] Consistency maintenance for constraint in role-based access control model
    Wei-li Han
    Gang Chen
    Jian-wei Yin
    Jin-xiang Dong
    Journal of Zhejiang University-SCIENCE A, 2002, 3 (3): : 292 - 297
  • [20] Consistency maintenance for constraint in role-based access control model
    韩伟力
    陈刚
    董金祥
    尹建伟
    Journal of Zhejiang University Science, 2002, (03) : 43 - 48