AMTRAC: An administrative model for temporal role-based access control

被引:8
|
作者
Sharma, Manisha [1 ]
Sural, Shamik [1 ]
Vaidya, Jaideep [2 ,3 ]
Atluri, Vijayalakshmi [2 ,3 ]
机构
[1] Indian Inst Technol, Sch Informat Technol, Kharagpur 721302, W Bengal, India
[2] Rutgers State Univ, MSIS Dept, Piscataway, NJ 08855 USA
[3] Rutgers State Univ, CIMIC, Piscataway, NJ 08855 USA
基金
美国国家科学基金会;
关键词
Administrative model; Temporal RBAC; Role enabling base assignment; Administrative command; Role hierarchy; PROTECTION;
D O I
10.1016/j.cose.2013.07.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Over the years, Role Based Access Control (RBAC) has received significant attention in system security and administration. The Temporal Role Based Access Control (TRBAC) model is an extension of RBAC that allows one to specify periodic enabling and disabling of roles in a role enabling base (REB). While decentralized administration and delegation of administrative responsibilities in large RBAC systems is managed using an administrative role based access control model like ARBAC97, no administrative model for TRBAC has yet been proposed. In this paper, we introduce such a model and name it AMTRAC (Administrative Model for Temporal Role based Access Control). AMTRAC defines a broad range of relations that control user-role assignment, role-permission assignment, role role assignment and role enabling base assignment. Since the first three are similar to those in ARBAC97, the role enabling base assignment component has been discussed in detail in this paper. The different ways by which role enabling conditions of regular roles can be modified are first explained. We then show how to specify which of the administrative roles are authorized to modify the role enabling conditions of any regular role. An exhaustive set of commands for authorization enforcement along with their pre and postconditions is also presented. Together, this would facilitate practical deployment and security analysis of TRBAC systems. (C) 2013 Elsevier Ltd. All rights reserved.
引用
收藏
页码:201 / 218
页数:18
相关论文
共 50 条
  • [1] A generalized temporal role-based access control model
    Joshi, JBD
    Bertino, E
    Latif, U
    Ghafoor, A
    [J]. IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2005, 17 (01) : 4 - 23
  • [2] Scalable and Precise Automated Analysis of Administrative Temporal Role-Based Access Control
    Ranise, Silvio
    Truong, Anh
    Armando, Alessandro
    [J]. PROCEEDINGS OF THE 19TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES (SACMAT'14), 2014, : 103 - 114
  • [3] An Administrative Model for Role-Based Access Control Using Hierarchical Namespace
    Xia, Luning
    Jing, Jiwu
    [J]. PACIFIC ASIA CONFERENCE ON INFORMATION SYSTEMS 2006, SECTIONS 1-8, 2006, : 181 - 188
  • [4] A spatio-temporal role-based access control model
    Ray, Indrakshi
    Toahchoodee, Manachai
    [J]. DATA AND APPLICATIONS SECURITY XXI, PROCEEDINGS, 2007, 4602 : 211 - +
  • [5] Policy analysis for Administrative Role-Based Access Control
    Sasturkar, Amit
    Yang, Ping
    Stoller, Scott D.
    Ramakrishnan, C. R.
    [J]. THEORETICAL COMPUTER SCIENCE, 2011, 412 (44) : 6208 - 6234
  • [6] Uni-ARBAC: A Unified Administrative Model for Role-Based Access Control
    Biswas, Prosunjit
    Sandhu, Ravi
    Krishnan, Ram
    [J]. INFORMATION SECURITY, (ISC 2016), 2016, 9866 : 218 - 230
  • [7] VAC - Verifier of Administrative Role-Based Access Control Policies
    Ferrara, Anna Lisa
    Madhusudan, P.
    Nguyen, Truc L.
    Parlato, Gennaro
    [J]. COMPUTER AIDED VERIFICATION, CAV 2014, 2014, 8559 : 184 - 191
  • [8] Planning User Assignment in Administrative Role-Based Access Control
    Huang, Wei
    Yang, Yang
    [J]. 2009 ISECS INTERNATIONAL COLLOQUIUM ON COMPUTING, COMMUNICATION, CONTROL, AND MANAGEMENT, VOL IV, 2009, : 615 - +
  • [9] On the formalization and analysis of a spatio-temporal role-based access control model
    Toahchoodee, Manachai
    Ray, Indrakshi
    [J]. JOURNAL OF COMPUTER SECURITY, 2011, 19 (03) : 399 - 452
  • [10] On the formal analysis of a spatio-temporal role-based access control model
    Toahchoodee, Manachai
    Ray, Indrakshi
    [J]. DATA AND APPLICATIONS SECURITY XXII, 2008, 5094 : 17 - 32