Role Delegation for a Distributed, Unified RBAC/MAC*
نویسندگان
چکیده
The day-today operations of corporations and government agencies rely on inter-operating legacy, COTs, databases, clients, servers, etc., which are brought together into a distributed environment running middleware (e.g., CORBA, JINI, DCOM, etc.). Both access control and security assurance within these distributed applications is paramount. Of particular concern is the delegation of authority, where an authorized individual (not the security officer) may delegate all or part of his/her authority to another individual, increasing security risk. The ability of an authorized individual to operate in a manner akin to a security officer, without oversight, must be carefully considered. This paper explores the definition and inclusion of role delegation into an existing distributed, unified role-based/mandatory access-control (RBAC/MAC) security model and enforcement framework. The RBAC/MAC model/framework controls access to software APIs to limit, by role, which users (clients) can access which parts of APIs, constrained by time, classification, and data values. This paper uses the RBAC/MAC model/enforcement framework as a context for a detailed examination of role delegation, including: the general characteristics of role delegation; the incorporation of role-delegation into the RBAC/MAC security model; and, the impact of role delegation on security assurance at design and run times.
منابع مشابه
Security Assurance for a Resource-based Rbac/dac/mac Security Model
middle model. These constructs are used to build security assurance rules and authorizations which will be presented in Chapter 5 and provide the basis for our security enforcement framework and prototype (see Chapter 6). The chapter details the design assumptions required to clearly establish the security model environment and security assurance requirements. This chapter concludes with a disc...
متن کاملComprehensive two-level analysis of role-based delegation and revocation policies with UML and OCL
Context. Role-based access control (RBAC) has become the de facto standard for access management in various large-scale organizations. Often rolebased policies must implement organizational rules to satisfy compliance or authorization requirements, e.g., the principle of separation of duty (SoD). To provide business continuity, organizations should also support the delegation of access rights a...
متن کاملModeling Support for Delegating Roles, Tasks, and Duties in a Process-Related RBAC Context
The definition of access control concepts at the modeling level is an important prerequisite for the thorough implementation and enforcement of corresponding policies and constraints in a software system. In this paper, we present an approach to provide modeling support for the delegation of roles, tasks, and duties in the context of processrelated RBAC models. The delegation model elements are...
متن کاملRB-GDM: A Role-Based Grid Delegation Model
Grid delegation is the procedure by which a valid user endows another user or a program or service with the ability to act on that user’s behalf. Delegation is the primary form of authorization in grids. The large and geographically distributed, dynamic, heterogeneous and scalable grid environment poses unique delegation requirements. Presently there are no standard mechanisms to guide grid del...
متن کاملA Unified Attribute-Based Access Control Model Covering DAC, MAC and RBAC
Recently, there has been considerable interest in attribute based access control (ABAC) to overcome the limitations of the dominant access control models (i.e, discretionary-DAC, mandatory-MAC and role based-RBAC) while unifying their advantages. Although some proposals for ABAC have been published, and even implemented and standardized, there is no consensus on precisely what is meant by ABAC ...
متن کامل