DS RBAC - Dynamic Sessions in Role Based Access Control

被引:0
|
作者
Muehlbacher, Joerg R. [1 ]
Praher, Christian [1 ]
机构
[1] Johannes Kepler Univ Linz, Linz, Austria
关键词
security; Role Based Access Control; ANSI RBAC; session; least privilege;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Besides the well established access control models, Discretionary Access Control (DAC) and Mandatory Access Control (MAC), the policy neutral Role Based Access Control (RBAC) is gaining increasingly momentum. An important step towards a wide acceptance of RBAC has been achieved by the standardization of RBAC through the American National Standards Institute (ANSI) in 2004. While the concept of sessions specified in the ANSI RBAC standard allows for differentiated role selections according to tasks that have to be performed by users, it is very likely that more roles will be activated in a session than are effectively needed to perform the intended activity. Dynamic Sessions in RBAC (DS RBAC) is an extension to the existing RBAC ANSI standard that dynamically deactivates roles in a session if they are not exercised for a certain period of time. This allows for the selection of an outer-shell of possibly needed permissions at the initation of a session through a user, while adhering to the principle of least privilege by automatically reducing the effective permission space to those roles really exercised in the session. Analogous to the working set model known from virtual memory, only the minimal roles containing permissions recently exercised by the user are left in a session in the DS RBAC model. If the user tries to access a role that has aged out due to inactivity, a role fault occurs. A role fault can be resolved by the role fault handler that is responsible for re-activating the expired role. As will be presented in this paper, role re-activation may be subject to constraints that have to be fulfilled by the user in order to re-access the aged role.
引用
收藏
页码:538 / 554
页数:17
相关论文
共 50 条
  • [41] Improved Access Control Strategy Based on RBAC Model and Its Application
    Cheng, Yin-lei
    Wang, Fang
    Shang, Lei-ming
    Wang, Biao-ren
    Xu, Juan
    [J]. PROCEEDINGS OF THE 2015 5TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCES AND AUTOMATION ENGINEERING, 2016, 42 : 808 - 813
  • [42] An XML-based language for access control specifications in an RBAC environment
    Stoupa, KE
    Vakali, AI
    [J]. 2003 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN AND CYBERNETICS, VOLS 1-5, CONFERENCE PROCEEDINGS, 2003, : 1717 - 1722
  • [43] RB-GACA: A RBAC based grid access control architecture
    Jin, Hai
    Qiang, Weizhong
    Shi, Xuanhua
    Zou, Deqing
    [J]. INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2005, 1 (01) : 61 - 70
  • [44] RB-GACA: A RBAC based grid access control architecture
    Qiang, WZ
    Jin, H
    Shi, XH
    Zou, DQ
    Zhang, H
    [J]. GRID AND COOPERATIVE COMPUTING, PT 1, 2004, 3032 : 487 - 494
  • [45] RBAC-Based Access Control Integration Framework for Legacy System
    Guo, He
    Lu, Guoji
    Wang, Yuxin
    Li, Han
    Chen, Xin
    [J]. WEB INFORMATION SYSTEMS AND MINING, 2010, 6318 : 194 - +
  • [46] An access control of enterprise financial privacy information based on RBAC model
    Shi, Xuejiao
    [J]. International Journal of Computer Applications in Technology, 2024, 74 (04) : 372 - 381
  • [47] Distributed access control method based on RBAC in OSGi service platform
    Cho, Eun-Ae
    Moon, Chang-Joo
    Baik, Doo-Kwon
    [J]. DYNAMICS OF CONTINUOUS DISCRETE AND IMPULSIVE SYSTEMS-SERIES B-APPLICATIONS & ALGORITHMS, 2007, 14 : 1427 - 1431
  • [48] RBAC-HDE: On the Design of a Role-based Access Control with Smart Contract for Healthcare Data Exchange
    Akkaoui, Raifa
    Hei, Xiaojun
    Guo, Charles
    Cheng, Wenqing
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS - TAIWAN (ICCE-TW), 2019,
  • [49] Improvement and implementation of RBAC access control model
    Information College, Capital University of Economics and Business, Beijing, China
    [J]. Proc. - Int. Conf. Manage. e-Commer. e-Govern., ICMeCG, 1600, (110-115):
  • [50] A Dynamic Access Control Model Using Authorising Workflow and Task-Role-Based Access Control
    Uddin, Mumina
    Islam, Shareeful
    Al-Nemrat, Ameer
    [J]. IEEE ACCESS, 2019, 7 : 166676 - 166689