A Dynamic Access Control Model Using Authorising Workflow and Task-Role-Based Access Control

被引:32
|
作者
Uddin, Mumina [1 ]
Islam, Shareeful [1 ]
Al-Nemrat, Ameer [1 ]
机构
[1] Univ East London, Sch Architecture Comp & Engn, London E16 2RD, England
来源
IEEE ACCESS | 2019年 / 7卷
关键词
Identity and access management; role based access control; extensible access control markup language; attribute access control; dynamic segregation of duties;
D O I
10.1109/ACCESS.2019.2947377
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Access control is fundamental and prerequisite to govern and safeguard information assets within an organisation. Organisations generally use web enabled remote access coupled with applications access distributed on the various networks facing various challenges including increase operation burden, monitoring issues due to the dynamic and complex nature of security policies for access control. The increasingly dynamic nature of collaborations means that in one context a user should have access to sensitive information and not applicable for another context. The current access control models are static and lack of Dynamic Segregation of Duties (SoD), Task instance level of Segregation and decision making in real time. This paper addresses the limitations and supports access management in borderless network environment with dynamic SoD capability at real time access control decision making and policy enforcement. This research makes three contributions: i) Defining an Authorising Workflow Task Role Based Access Control using the existing task and workflow concepts. It integrates the dynamic SoD considering the task instance restriction to ensure overall access governance and accountability. It enhances the existing access control models such as RBAC by dynamically granting users access right and providing Access governance. ii) Extended the OASIS standard of XACML policy language to support the dynamic access control requirements and enforce the access control rules for real time decision making to mitigate risk relating to access control such as escalation of privilege in broken access control and insufficient logging and monitoring iii) The model is implemented using open source Balana policy engine to demonstrate its applicability to a real industrial use case from a financial institution. The results show that, AW-TRBAC is scalable consuming relatively large number of complex request and able to meet the requirements of dynamic access control characteristics.
引用
收藏
页码:166676 / 166689
页数:14
相关论文
共 50 条
  • [1] Task-role-based access control model
    Oh, S
    Park, S
    [J]. INFORMATION SYSTEMS, 2003, 28 (06) : 533 - 562
  • [2] Task-role-based access control in application on MIS
    Zhang, Li
    Luo, Lili
    Zhang, Liyong
    Geng, Tiesuo
    Yue, Zongge
    [J]. APSCC: 2006 IEEE ASIA-PACIFIC CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, 2006, : 153 - +
  • [3] Task-role-based Access Control Model in Smart Health-care System
    Wang, Peng
    Jiang, Lingyun
    [J]. INTERNATIONAL CONFERENCE ON ENGINEERING TECHNOLOGY AND APPLICATION (ICETA 2015), 2015, 22
  • [4] Towards an Attribute-Based Authorization Model with Task-Role-Based Access Control for WfMS
    Liu, Kui
    Zhou, Zhurong
    Chen, Qianguo
    Yang, Xiaoli
    [J]. 2015 IEEE 16TH INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY (ICCT), 2015, : 361 - 371
  • [5] A Task-and-Role-Based Access Control Model for Workflow System
    yi, Xu
    [J]. DCABES 2008 PROCEEDINGS, VOLS I AND II, 2008, : 843 - 846
  • [6] An Organization and Task Based Access Control Model for Workflow System
    Wang, Baoyi
    Zhang, Shaomin
    [J]. ADVANCES IN WEB AND NETWORK TECHNOLOGIES, AND INFORMATION MANAGEMENT, PROCEEDINGS, 2007, 4537 : 485 - 490
  • [7] A Role-Based Workflow Access Control Model
    Zhang Wen-dong
    Zhang Kai-ji
    [J]. PROCEEDINGS OF THE FIRST INTERNATIONAL WORKSHOP ON EDUCATION TECHNOLOGY AND COMPUTER SCIENCE, VOL II, 2009, : 1136 - 1139
  • [8] An access control model based on organization and task in workflow for power system
    Wang, Baoyi
    Yu, Xiaobo
    [J]. Dianli Xitong Zidonghua/Automation of Electric Power Systems, 2007, 31 (04): : 51 - 55
  • [9] Researches on the access secure control workflow model based on role
    Zhai, Jinbiao
    [J]. Journal of Chemical and Pharmaceutical Research, 2014, 6 (02) : 101 - 109
  • [10] Workflow and Role Based Access Control Model for Cloud Manufacturing
    Lin, Xianhui
    Zhang, Xiaomei
    [J]. 2013 IEEE 11TH INTERNATIONAL CONFERENCE ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING (DASC), 2013, : 65 - 71