Abstract:
Abstract The basic concept of role-based access control (RBAC) is that permissions are associated with roles, and users are made members of appropriate roles thereby acquiring the roles ' permissions. This idea has been around since the advent of multi-user computing. Until recently, however, RBAC has received little attention from the research community. This article describes the motivations, results and open issues in recent RBAC research. The article focuses on four areas. Firstly, RBAC is a multi-dimensional concept that can range from very simple at one extreme to quite complex and sophisticated at the other. This presents problems in coming up with a definitive model of RBAC. We see how this impasse is resolved by having a family of models which can accommodate all these variations. Secondly, we discuss how RBAC can be used to manage itself. Recent models developed for this purpose are presented. Thirdly, the flexibility of RBAC can be demonstrated in many ways. Here we show how RBAC can be configured to enforce different variations of classical lattice-based mandatory access controls. Fourthly, we describe a
Citations
|
665
|
Role-based access control models
– Sandhu, Coyne, et al.
- 1996
|
|
179
|
RoleBased Access Control
– Ferraiolo, Kuhn, et al.
- 2003
|
|
94
|
The typed access matrix model
– Sandhu
- 1992
|
|
67
|
Transaction control expressions for separation of duties
– Sandhu
- 1988
|
|
57
|
Access rights administration in role-based security systems
– Nyanchama, Osborn
- 1994
|
|
47
|
Role hierarchies and constraints for lattice-based access controls
– SANDHU
- 1996
|
|
40
|
Naming and Grouping Privileges to Simplify Security Management
– Baldwin
- 1990
|
|
38
|
Separation of duties in computerized information systems
– Sandhu
- 1991
|
|
26
|
An examination of federal and commercial access control policy needs
– Ferraiolo, Gilbert, et al.
- 1993
|
|
19
|
Design for dynamic user-role-based security
– Mohammed, Dilts
- 1994
|
|
19
|
Delegation of authority
– MOFFETT, SLOMAN
- 1991
|
|
18
|
A new model for role-based access control
– Guiri
- 1995
|
|
17
|
User-role based security in the ADAM object-oriented design and analyses environment
– Hu, Demurjian, et al.
- 1995
|
|
16
|
Secure Computer Systems: A Network Interpretation
– Bell
- 1986
|
|
13
|
Using mandatory integrity to enforce "commercial" security
– Lee
- 1988
|
|
9
|
Criteria Editorial Board. Common Criteria for Information Technology Security
– Common
- 1996
|
|
7
|
Role-based access control in ORACLE7 and Trusted ORACLE7
– Notargiacomo
- 1995
|
|
5
|
Extending access controls with duties|realized by active mechanisms
– Jonscher
- 1993
|