Scalable Role & Organization Based Access Control and Its Administration

نویسنده

  • Zhixiong Zhang
چکیده

SCALABLE ROLE & ORGANIZATION BASED ACCESS CONTROL AND ITS ADMINISTRATION Zhixiong Zhang, Ph.D. George Mason University, 2008 Dissertation Co-director: Dr. Ravi S. Sandhu Dissertation Co-director: Dr. Daniel Menascé In Role Based Access Control (RBAC), roles are typically created based on job functions inside an organization. Traditional RBAC does not scale up well for modeling security policies spanning multiple organizations. To solve this problem, a family of extended RBAC models called Role and Organization Based Access Control (ROBAC) models and its administrative models are proposed and formalized in this dissertation. Two examples are used to motivate and demonstrate the usefulness of ROBAC. Comparison between ROBAC and other RBAC extensions are given. I show that ROBAC can significantly reduce the administrative complexities of applications involving a large number of similar organizational units. The applicability and expressive power of ROBAC are discussed. By showing that any given ROBAC model can be modeled by a RBAC model and vice versa, I prove that the expressive power of ROBAC is equal to that of traditional RBAC. A comprehensive role and organization based administrative model called AROBAC07 is developed. It has five sub-models dealing with various administrative tasks in ROBAC. I show that the AROBAC07 model provides an intuitive and controlled way to decentralize administrative tasks in ROBAC based systems. A concept called application compartment (ACom) in ROBAC is introduced and its usage in ROBAC is discussed. AROBAC07 scales up very well for ROBAC based systems involving many organizational units. Two ROBAC variants, manifold ROBAC (ROBAC) and pseudo ROBAC (ROBAC), are presented and formalized. Their corresponding administrative models are also proposed. The usefulness of manifold ROBAC is demonstrated in secure collaboration via a ROBAC based secure collaboration schema which avoids many problems resulted from role-mapping, role-translation, or role exporting. The usefulness of pseudo ROBAC is demonstrated in a web based on-demand movie service case study.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Authorization models for secure information sharing: a survey and research agenda

This article presents a survey of authorization models and considers their 'fitness-for-purpose' in facilitating information sharing. Network-supported information sharing is an important technical capability that underpins collaboration in support of dynamic and unpredictable activities such as emergency response, national security, infrastructure protection, supply chain integration and emerg...

متن کامل

Towards a Scalable Role and Organization Based Access Control Model with Decentralized Security Administration

AbStrAct This chapter addresses the problem that traditional role-base access control (RBAC) models do not scale up well for modeling security policies spanning multiple organizations. After reviewing recently proposed Role and Organization Based Access Control (ROBAC) models, an administrative ROBAC model called AROBAC07 is presented and formalized in this chapter. Two examples are used to mot...

متن کامل

Management of access control in information system based on role concept

Development of technology, progress and increase of information flow have the impact also on the development of enterprises and require rapid changes in their information systems. The growth and complexity of functionality that they currently should face cause that their design and realization become the difficult tasks and strategic for the enterprises at the same time. The informations system...

متن کامل

Administration in Role - Based Security Systems 1

This paper examines the concept of role-based protection and, in particular, role organization. From basic role relationships, a model for role organization is developed. The role graph model, its operator semantics based on graph theory and algorithms for role administration are proposed. The role graph model, in our view, presents a very generalized form of role organization for access rights...

متن کامل

A combination of semantic and attribute-based access control model for virtual organizations

A Virtual Organization (VO) consists of some real organizations with common interests, which aims to provide inter organizational associations to reach some common goals by sharing their resources with each other. Providing security mechanisms, and especially a suitable access control mechanism, which enforces the defined security policy is a necessary requirement in VOs. Since VO is a complex ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008