Role-based access control for a distributed calculus

被引:7
|
作者
Braghin, Chiara [1 ]
Gorla, Daniele [2 ]
Sassone, Vladimiro [3 ]
机构
[1] Univ Ca Foscari Venezia, Dip Informat, Venice, Italy
[2] Univ Roma La Sapienza, Dip Informat, Rome, Italy
[3] Univ Sussex, Dept Informat, Brighton, E Sussex, England
关键词
RBAC; process calculi; Type Systems; Behavioural Equivalences;
D O I
10.3233/JCS-2006-14202
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Role-based access control (RBAC) is increasingly attracting attention because it reduces the complexity and cost of security administration by interposing the notion of role in the assignment of permissions to users. In this paper, we present a formal framework relying on an extension of the p-calculus to study the behaviour of concurrent systems in a RBAC scenario. We define a type system ensuring that the specified policy is respected during computations, and a behavioural equivalence to equate systems. We then consider a more sophisticated feature that can be easily integrated in our framework, i.e., the possibility of automatically adding role activations and deactivations to processes to be run under a given policy (whenever possible). Finally, we show how the framework can be easily extended to express significant extensions of the core RBAC model, such as roles hierarchies or constraints determining the acceptability of the system components.
引用
收藏
页码:113 / 155
页数:43
相关论文
共 50 条
  • [1] A distributed calculus for role-based access control
    Braghin, C
    Gorla, D
    Sassone, V
    [J]. 17TH IEEE COMPUTER SECURITY FOUNDATIONS WORKSHOP, PROCEEDINGS, 2004, : 48 - 60
  • [2] Distributed Role-based Access Control for Coaliagion Application
    HONG Fan ZHU Xian XING GuanglinHONG Fan
    [J]. Geo-spatial Information Science, 2005, (02) : 138 - 143
  • [3] Distributed Role-based Access Control for Coaliagion Application
    Hong Fan
    Zhu Xian
    Xing Guanglin
    [J]. GEO-SPATIAL INFORMATION SCIENCE, 2005, 8 (02) : 138 - 143
  • [4] Role-based access control for CORBA distributed object systems
    Obelheiro, RR
    Fraga, JS
    [J]. PROCEEDINGS OF THE SEVENTH IEEE INTERNATIONAL WORKSHOP ON OBJECT-ORIENTED REAL-TIME DEPENDABLE SYSTEMS, 2002, : 53 - 60
  • [5] Hardware-Enhanced Distributed Access Enforcement for Role-Based Access Control
    Bloom, Gedare
    Simha, Rahul
    [J]. PROCEEDINGS OF THE 19TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES (SACMAT'14), 2014, : 5 - 15
  • [6] Efficient Access Enforcement in Distributed Role-Based Access Control (RBAC) Deployments
    Tripunitara, Mahesh V.
    Carbunar, Bogdan
    [J]. SACMAT'09: PROCEEDINGS OF THE 14TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2009, : 155 - 164
  • [7] Role-based access control and the access control matrix
    Saunders, G
    Hitchens, M
    Varadharajan, V
    [J]. INFORMATION AND COMMUNICATIONS SECURITY, PROCEEDINGS, 2003, 2836 : 145 - 157
  • [8] dRBAC: Distributed role-based access control for dynamic coalition environments
    Freudenthal, E
    Pesin, T
    Port, L
    Keenan, E
    Karamcheti, V
    [J]. 22ND INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS, PROCEEDINGS, 2002, : 411 - 420
  • [9] Early Validation and Verification of a Distributed Role-Based Access Control Model
    Zafar, Saad
    Colvin, Robert
    Winter, Kirsten
    Yatapanage, Nisansala
    Dromey, R. G.
    [J]. 14TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE, PROCEEDINGS, 2007, : 430 - +
  • [10] Meta-policies for distributed role-based access control systems
    Belokosztolszki, A
    Moody, K
    [J]. THIRD INTERNATION WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2002, : 106 - 115