GTHBAC: A Generalized Temporal History Based Access Control Model

被引:1
|
作者
Ravari, Ali Noorollahi [1 ]
Jafarian, Jafar Haadi [1 ]
Amini, Morteza [1 ]
Jalili, Rasool [1 ]
机构
[1] Sharif Univ Technol, Dept Comp Engn, Sharif Network Secur Ctr, Tehran, Iran
关键词
Access control; Semantic-awareness; Temporal authorization; Access history;
D O I
10.1007/s11235-009-9239-9
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Time plays a crucial role in access control for new computing environments, which is not supported in traditional access control models. In this paper, we propose a Generalized Temporal History Based Access Control (GTHBAC) model, aimed at integrating history-based constraints along with a generic access control model. GTHBAC enhances the specification of user-defined authorization rules by constraining time interval and temporal expression over users' history of accesses. Due to different application needs, GTHBAC uses two different time schemes, i.e., real time and logical time, in its authorization rules. A formal semantics for temporal authorizations is provided, and conflicting situations are also investigated and resolved in the model. To represent the applicability of the proposed model, an architecture for an access control system based on the model is proposed, and a case of employing the model in specifying and enforcing access control policies in a banking system is studied. The operators of GTHBAC are also compared with Linear Time Temporal Logic.(LTL) operators to show the expressive power of the model.
引用
收藏
页码:111 / 125
页数:15
相关论文
共 50 条
  • [1] GTHBAC: A Generalized Temporal History Based Access Control Model
    Ali Noorollahi Ravari
    Jafar Haadi Jafarian
    Morteza Amini
    Rasool Jalili
    [J]. Telecommunication Systems, 2010, 45 : 111 - 125
  • [2] A generalized temporal role-based access control model
    Joshi, JBD
    Bertino, E
    Latif, U
    Ghafoor, A
    [J]. IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2005, 17 (01) : 4 - 23
  • [3] Hybrid role hierarchy for generalized temporal role based access control model
    Joshi, JBD
    Bertino, E
    Ghafoor, A
    [J]. 26TH ANNUAL INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE, PROCEEDINGS, 2002, : 951 - 956
  • [4] An analysis of expressiveness and design issues for the generalized temporal role-based access control model
    Joshi, JBD
    Bertino, E
    Ghafoor, A
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2005, 2 (02) : 157 - 175
  • [5] A Location Temporal Based Access Control Model for IoTs
    Lee, Chao
    Guo, Yunchuan
    Yin, Lihua
    [J]. 2013 AASRI CONFERENCE ON PARALLEL AND DISTRIBUTED COMPUTING AND SYSTEMS, 2013, 5 : 15 - 20
  • [6] A Temporal Semantic-Based Access Control Model
    Ravari, Ali Noorollahi
    Amini, Morteza
    Jalili, Rasool
    [J]. ADVANCES IN COMPUTER SCIENCE AND ENGINEERING, 2008, 6 : 559 - 568
  • [7] Specification, Validation, and Enforcement of a Generalized Spatio-Temporal Role-Based Access Control Model
    Abdunabi, Ramadan
    Al-Lail, Mustafa
    Ray, Indrakshi
    France, Robert B.
    [J]. IEEE SYSTEMS JOURNAL, 2013, 7 (03): : 501 - 515
  • [8] A Temporal Description Logic Based Access Control Model for Expressing History Constrained Policies in Semantic Web
    Faghih, Fathieh
    Amini, Morteza
    Jalili, Rasool
    [J]. 2009 IEEE INTERNATIONAL SYMPOSIUM ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, 2009, : 142 - 149
  • [9] A spatio-temporal role-based access control model
    Ray, Indrakshi
    Toahchoodee, Manachai
    [J]. DATA AND APPLICATIONS SECURITY XXI, PROCEEDINGS, 2007, 4602 : 211 - +
  • [10] AMTRAC: An administrative model for temporal role-based access control
    Sharma, Manisha
    Sural, Shamik
    Vaidya, Jaideep
    Atluri, Vijayalakshmi
    [J]. COMPUTERS & SECURITY, 2013, 39 : 201 - 218