This paper introduces TDL-RGTA, a formal Temporal Defeasible Logic framework that enhances Role-Based Access Control (RBAC) by integrating organizational groups and contextual tasks into a dynamic, logic-based authorization model. Conventional RBAC and its temporal variants (TRBAC) are inherently static, struggling with real-time policy conflicts, context-specific exceptions, and the need for explainable decisions. TDL-RGTA addresses these limitations by employing defeasible reasoning under temporal constraints, in which permissions are dynamically derived from an agent’s role, active group membership, and task context. The framework introduces three key innovations: 1) group-task binding, which scopes role permissions to specific departmental contexts; 2) localized role hierarchies, which confine inherited permissions within an organizational group to prevent cross-departmental privilege leaks; and 3) structured, rule-based explanations, which provide transparent, auditable trails for every access decision by logging the rules triggered and overridden during reasoning; and 4) automated, distributed enforcement of the Separation of Duties across organizational boundaries. A hospital emergency-response case study demonstrates how TDL-RGTA maintains security, adapts in real-time to emergencies, and provides a formal foundation for compliance with standards such as NIST SP 800-53. The results establish TDL-RGTA as a secure, adaptive, and explainable access control framework, particularly well-suited for complex, decentralized environments, such as multi-agent systems.
更多