Towards Session-aware RBAC Administration and Enforcement with XACML

被引:4
|
作者
Xu, Min [1 ]
Wijesekera, Duminda [1 ]
Zhang, Xinwen [2 ]
Cooray, Deshan [1 ]
机构
[1] George Mason Univ, Dept Comp Sci, Fairfax, VA 22030 USA
[2] Samsung Informat Syst Amer, Comp Sci Lab, San Jose, CA USA
关键词
D O I
10.1109/POLICY.2009.27
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
An administrative role-based access control (ARBAC) model specifies administrative policies over a role-based access control (RBAC) system, where an administrative permission may change an RBAC policy by updating permissions assigned to roles, or assigning/revoking users to/from roles. Consequently, enforcing ARBAC policies over an active access controller while some users are using protected resources would result in conflicts: a policy may be in effect in the RBAC system while being updated by an ARBAC operation. Towards solving this concurrency problem, we propose a session-aware administrative model for RBAC. We show how the concurrency problem can be resolved by enhancing the eXtensible Access Control Markup Language (XACML) reference implementation. In order to do so, we develop an XACML-ARBAC profile to specify ARBAC policies, and enforce these polices by building an ARBAC enforcement module and a session administrative module. The former synchronizes with the evaluation of access control requests. The latter revokes conflicting ongoing user sessions immediately prior to enforcing administrative operations. Experimental studies show reasonable performance characteristics of our initial enhancement to Sun's reference implementation.
引用
收藏
页码:9 / +
页数:2
相关论文
共 50 条
  • [41] Session-Aware Query Auto-completion using Extreme Multi-Label Ranking
    Yadav, Nishant
    Sen, Rajat
    Hill, Daniel N.
    Mazumdar, Arya
    Dhillon, Inderjit S.
    KDD '21: PROCEEDINGS OF THE 27TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY & DATA MINING, 2021, : 3835 - 3844
  • [42] CrossIndex: Memory-Friendly and Session-Aware Index for Supporting Crossfilter in Interactive Data Exploration
    Xia, Tianyu
    Zhang, Hanbing
    Jing, Yinan
    He, Zhenying
    Zhang, Kai
    Wang, X. Sean
    DATABASE SYSTEMS FOR ADVANCED APPLICATIONS, DASFAA 2022, PT I, 2022, : 476 - 492
  • [43] Optimizing Session-Aware Recommenders: A Deep Dive into GRU-Based Latent Interaction Integration
    Lin, Ming-Yen
    Wu, Ping-Chun
    Hsueh, Sue-Chen
    FUTURE INTERNET, 2024, 16 (02)
  • [44] Session-aware news recommendations using random walks on time-evolving heterogeneous information networks
    Symeonidis, Panagiotis
    Kirjackaja, Lidija
    Zanker, Markus
    USER MODELING AND USER-ADAPTED INTERACTION, 2020, 30 (04) : 727 - 755
  • [45] LARBAC: ENFORCEMENT OF LOCATION CONSTRAINTS FOR LOCATION-AWARE RBAC SYSTEM IN MOBILE ENVIRONMENT
    Sarean, Rinardi B.
    Jeng, Albert B.
    Lee, Hahn-Ming
    PROCEEDINGS OF 2013 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS (ICMLC), VOLS 1-4, 2013, : 1195 - 1200
  • [46] Session-aware news recommendations using random walks on time-evolving heterogeneous information networks
    Panagiotis Symeonidis
    Lidija Kirjackaja
    Markus Zanker
    User Modeling and User-Adapted Interaction, 2020, 30 : 727 - 755
  • [47] Hierarchical domains for decentralized administration of spatially-aware RBAC systems
    Damiani, Maria Luisa
    Silvestri, Claudio
    Bertino, Elisa
    ARES 2008: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON AVAILABILITY, SECURITY AND RELIABILITY, 2008, : 153 - +
  • [48] Towards a Flexible Framework to Support a Generalized Extension of XACML for Spatio-temporal RBAC Model with Reasoning Ability
    Tuan Ngoc Nguyen
    Kim Tuyen Le Thi
    Anh Tuan Dang
    Ha Duc Son Van
    Tran Khanh Dang
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2013, PT V, 2013, 7975 : 437 - 451
  • [49] Towards a flexible framework to support a generalized extension of XACML for spatio-temporal RBAC model with reasoning ability
    Tran Khanh Dang
    Tuyen Thi Kim Le
    Anh Tuan Dang
    Ha Duc Son Van
    INTERNATIONAL JOURNAL OF WEB INFORMATION SYSTEMS, 2014, 10 (02) : 131 - 150