Towards Session-aware RBAC Administration and Enforcement with XACML

被引:4
|
作者
Xu, Min [1 ]
Wijesekera, Duminda [1 ]
Zhang, Xinwen [2 ]
Cooray, Deshan [1 ]
机构
[1] George Mason Univ, Dept Comp Sci, Fairfax, VA 22030 USA
[2] Samsung Informat Syst Amer, Comp Sci Lab, San Jose, CA USA
关键词
D O I
10.1109/POLICY.2009.27
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
An administrative role-based access control (ARBAC) model specifies administrative policies over a role-based access control (RBAC) system, where an administrative permission may change an RBAC policy by updating permissions assigned to roles, or assigning/revoking users to/from roles. Consequently, enforcing ARBAC policies over an active access controller while some users are using protected resources would result in conflicts: a policy may be in effect in the RBAC system while being updated by an ARBAC operation. Towards solving this concurrency problem, we propose a session-aware administrative model for RBAC. We show how the concurrency problem can be resolved by enhancing the eXtensible Access Control Markup Language (XACML) reference implementation. In order to do so, we develop an XACML-ARBAC profile to specify ARBAC policies, and enforce these polices by building an ARBAC enforcement module and a session administrative module. The former synchronizes with the evaluation of access control requests. The latter revokes conflicting ongoing user sessions immediately prior to enforcing administrative operations. Experimental studies show reasonable performance characteristics of our initial enhancement to Sun's reference implementation.
引用
收藏
页码:9 / +
页数:2
相关论文
共 50 条
  • [21] Privacy-Preserving Enforcement of Spatially Aware RBAC
    Kirkpatrick, Michael S.
    Ghinita, Gabriel
    Bertino, Elisa
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2012, 9 (05) : 627 - 640
  • [22] Session-aware Linear Item-Item Models for Session-based Recommendation
    Choi, Minjin
    Kim, Jinhong
    Lee, Joonseok
    Shim, Hyunjung
    Lee, Jongwuk
    PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE 2021 (WWW 2021), 2021, : 2186 - 2197
  • [23] Modelling Contextual Information in Session-Aware Recommender Systems with Neural Networks
    Twardowski, Bartlomiej
    PROCEEDINGS OF THE 10TH ACM CONFERENCE ON RECOMMENDER SYSTEMS (RECSYS'16), 2016, : 273 - 276
  • [24] Personalized Graph Neural Networks With Attention Mechanism for Session-Aware Recommendation
    Zhang, Mengqi
    Wu, Shu
    Gao, Meng
    Jiang, Xin
    Xu, Ke
    Wang, Liang
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2022, 34 (08) : 3946 - 3957
  • [25] Signaling protocol for session-aware popularity-based resource allocation
    Mendes, P
    Schulzrinne, H
    Monteiro, E
    MANAGEMENT OF MULTIMEDIA ON THE INTERNET, 2002, 2496 : 101 - 113
  • [26] Session-aware Information Embedding for E-commerce Product Recommendation
    Wu, Chen
    Yan, Ming
    CIKM'17: PROCEEDINGS OF THE 2017 ACM CONFERENCE ON INFORMATION AND KNOWLEDGE MANAGEMENT, 2017, : 2379 - 2382
  • [27] MTSI-BERT: A Session-aware Knowledge-based Conversational Agent
    Senese, Matteo A.
    Rizzo, Giuseppe
    Dragoni, Mauro
    Morisio, Maurizio
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON LANGUAGE RESOURCES AND EVALUATION (LREC 2020), 2020, : 717 - 725
  • [28] Session-aware recommender system using double deep reinforcement learning
    Khurana, Purnima
    Gupta, Bhavna
    Sharma, Ravish
    Bedi, Punam
    JOURNAL OF INTELLIGENT INFORMATION SYSTEMS, 2024, 62 (02) : 403 - 429
  • [29] MUSAQ: A multimedia session-aware QoS provisioning scheme for cellular networks
    Rizvi, Mona Ei-Kadi
    Olariu, Stephan
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2008, 8 (03): : 343 - 354
  • [30] Session-aware recommender system using double deep reinforcement learning
    Purnima Khurana
    Bhavna Gupta
    Ravish Sharma
    Punam Bedi
    Journal of Intelligent Information Systems, 2024, 62 : 403 - 429