Towards Session-aware RBAC Administration and Enforcement with XACML

被引:4
|
作者
Xu, Min [1 ]
Wijesekera, Duminda [1 ]
Zhang, Xinwen [2 ]
Cooray, Deshan [1 ]
机构
[1] George Mason Univ, Dept Comp Sci, Fairfax, VA 22030 USA
[2] Samsung Informat Syst Amer, Comp Sci Lab, San Jose, CA USA
关键词
D O I
10.1109/POLICY.2009.27
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
An administrative role-based access control (ARBAC) model specifies administrative policies over a role-based access control (RBAC) system, where an administrative permission may change an RBAC policy by updating permissions assigned to roles, or assigning/revoking users to/from roles. Consequently, enforcing ARBAC policies over an active access controller while some users are using protected resources would result in conflicts: a policy may be in effect in the RBAC system while being updated by an ARBAC operation. Towards solving this concurrency problem, we propose a session-aware administrative model for RBAC. We show how the concurrency problem can be resolved by enhancing the eXtensible Access Control Markup Language (XACML) reference implementation. In order to do so, we develop an XACML-ARBAC profile to specify ARBAC policies, and enforce these polices by building an ARBAC enforcement module and a session administrative module. The former synchronizes with the evaluation of access control requests. The latter revokes conflicting ongoing user sessions immediately prior to enforcing administrative operations. Experimental studies show reasonable performance characteristics of our initial enhancement to Sun's reference implementation.
引用
收藏
页码:9 / +
页数:2
相关论文
共 50 条
  • [31] Session-aware queue scheduling for improving performance of web applications under overload
    Matsunuma, Masahiro
    Kourai, Kenichi
    Hibino, Hideaki
    Chiba, Shigeru
    Sato, Yoshiki
    Computer Software, 2006, 23 (02) : 199 - 210
  • [32] Session-Aware Popularity-Based Resource Allocation for assured differentiated services
    Mendes, P
    Schulzrinne, H
    Monteiro, E
    IEEE COMMUNICATIONS MAGAZINE, 2002, 40 (09) : 104 - 111
  • [33] SSL/TLS Session-Aware User Authentication Using a GAA Bootstrapped Key
    Chen, Chunhua
    Mitchell, Chris J.
    Tang, Shaohua
    INFORMATION SECURITY THEORY AND PRACTICE: SECURITY AND PRIVACY OF MOBILE DEVICES IN WIRELESS COMMUNICATION, 2011, 6633 : 54 - 68
  • [34] Evaluating Session-Aware Admission-Control Strategies to Improve the Profitability of Service Providers
    Ayari, Narjess
    Barbaron, Denis
    Lefevre, Laurent
    2009 IEEE GLOBECOM WORKSHOPS, 2009, : 328 - +
  • [35] Parameter-Efficiently Leveraging Session Information in Deep Learning-Based Session-Aware Sequential Recommendation
    Seol, Jinseok
    Ko, Youngrok
    Lee, Sang-Goo
    IEEE ACCESS, 2025, 13 : 35555 - 35566
  • [36] A Neighbor-Guided Memory-Based Neural Network for Session-Aware Recommendation
    Yupu, Guo
    Yanxiang, Ling
    Chen, Honghui
    IEEE ACCESS, 2020, 8 : 120668 - 120678
  • [37] SSL/TLS session-aware user authentication - Or how to effectively thwart the man-in-the-middle
    Oppliger, Rolf
    Hauser, Ralf
    Basin, David
    COMPUTER COMMUNICATIONS, 2006, 29 (12) : 2238 - 2246
  • [38] MHGNN: Hybrid Graph Neural Network with Mixers for Multi-interest Session-Aware Recommendation
    Cui, Mingyu
    Peng, Zhaohui
    Chu, Yaohui
    Lu, Jikun
    Tan, Yashu
    WEB AND BIG DATA, APWEB-WAIM 2024, PT II, 2024, 14962 : 115 - 129
  • [39] MISS: A Multi-user Identification Network for Shared-Account Session-Aware Recommendation
    Wen, Xinyu
    Peng, Zhaohui
    Huang, Shanshan
    Wang, Senzhang
    Yu, Philip S.
    DATABASE SYSTEMS FOR ADVANCED APPLICATIONS (DASFAA 2021), PT III, 2021, 12683 : 228 - 243
  • [40] FSASA: Sequential Recommendation Based on Fusing Session-Aware Models and Self-Attention Networks
    Guo, Shangzhi
    Liao, Xiaofeng
    Meng, Fei
    Zhao, Qing
    Tang, Yuling
    Li, Hui
    Zong, Qinqin
    COMPUTER SCIENCE AND INFORMATION SYSTEMS, 2024, 21 (01) : 1 - 20