Spatio Temporal Emergency Role Based Access Control (STEM-RBAC) A Time and Location Aware Role Based Access Control Model with a Break the Glass Mechanism

被引:0
|
作者
Georgakakis, Emmanouil [1 ]
Nikolidakis, Stefanos A. [1 ]
Vergados, Dimitrios D. [1 ]
Douligeris, Christos [1 ]
机构
[1] Univ Piraeus, Dept Informat, Piraeus, Greece
关键词
component; Emergency Access; Break The Glass; Electronic Healthcare Record; Spatio Temporal RBAC; Access control;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The ever-increasing use of information systems and networks in every aspect of our lives has made possible the transfer of data to a wide range of different users and applications. In recent years, several architectures and models have been proposed in order to limit access to resources and ensure that data are available only to authorized users, programs or processes. These models in most cases are not dynamic and the permissions assigned to users are granted based on a static policy. A mechanism that will allow exception access to data, for example to medical information, in case of an emergency is needed. In current systems, emergency access techniques are not well defined and are used in an ad hoc manner on top of the access control mechanisms implemented without using parameters such as time, location or hierarchy of the actors involved in the system. In this paper, we present a model that provides both a normal access control based on roles and also a mechanism that is used in order to provide exception access to data in case of an emergency. The proposed emergency access mechanism is time aware and takes into account the mobility and location of users, also it grants exception access with a controlled manner in case of an emergency utilizing role hierarchies.
引用
收藏
页数:7
相关论文
共 50 条
  • [1] A spatio-temporal role-based access control model
    Ray, Indrakshi
    Toahchoodee, Manachai
    [J]. DATA AND APPLICATIONS SECURITY XXI, PROCEEDINGS, 2007, 4602 : 211 - +
  • [2] Spatio-Temporal Role Based Access Control for Physical Access Control Systems
    Geepalla, Emsaieb
    Bordbar, Behzad
    Du, Xiaofeng
    [J]. 2013 FOURTH INTERNATIONAL CONFERENCE ON EMERGING SECURITY TECHNOLOGIES (EST), 2013, : 39 - 42
  • [3] LRBAC: A Location-aware Role-Based Access Control model
    Ray, Indrakshi
    Kumar, Mahendra
    Yu, Lijun
    [J]. INFORMATION SYSTEMS SECURITY, PROCEEDINGS, 2006, 4332 : 147 - +
  • [4] A RBAC-Based Multitask Spatio-Temporal Access Control Model MT_RBAC
    Ying, Zhang
    Zhen, Xu
    Chi, Chen
    [J]. PROCEEDINGS OF 2018 INTERNATIONAL CONFERENCE ON COMPUTING AND PATTERN RECOGNITION (ICCPR 2018), 2018, : 14 - 20
  • [5] λ-RBAC: PROGRAMMING WITH ROLE-BASED ACCESS CONTROL
    Jagadeesan, Radha
    Jeffrey, Alan
    Pitcher, Corin
    Riely, James
    [J]. LOGICAL METHODS IN COMPUTER SCIENCE, 2008, 4 (01)
  • [6] λ-RBAC:: Programming with role-based access control
    Jagadeesan, Radha
    Jeffrey, Alan
    Pitcher, Corin
    Riely, James
    [J]. AUTOMATA, LANGUAGES AND PROGRAMMING, PT 2, 2006, 4052 : 456 - 467
  • [7] On the formalization and analysis of a spatio-temporal role-based access control model
    Toahchoodee, Manachai
    Ray, Indrakshi
    [J]. JOURNAL OF COMPUTER SECURITY, 2011, 19 (03) : 399 - 452
  • [8] On the formal analysis of a spatio-temporal role-based access control model
    Toahchoodee, Manachai
    Ray, Indrakshi
    [J]. DATA AND APPLICATIONS SECURITY XXII, 2008, 5094 : 17 - 32
  • [9] Emergency role-based access control (E-RBAC) and analysis of model specifications with alloy
    Nazerian, Fatemeh
    Motameni, Homayun
    Nematzadeh, Hossein
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2019, 45 : 131 - 142
  • [10] DS RBAC - Dynamic Sessions in Role Based Access Control
    Muehlbacher, Joerg R.
    Praher, Christian
    [J]. JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2009, 15 (03) : 538 - 554