An Extended Role-Based Access Control Model for Delegating Obligations

TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, PROCEEDINGS(2009)

引用 10|浏览0
暂无评分
摘要
The main aim of access control models is to provide means to simplify the management of the security policy, which is a fastidious and error-prone task. Supporting delegation is considered as an important mean to decentralize the administration and therefore to allow security policy to be more flexible and easier to manipulate. Our main contribution is the proposition of a unified model to the administration and delegation of obligations. Managing such delegations implies more requirements than managing traditional privileges delegation. In fact, delegating obligations may include two interpretations: the delegation of the obligation and the delegation of the responsibility related to this obligation. Therefore, it is important to deal with these two notions separately. Moreover, since delegating an obligation involves the delegation of sanctions, then the consent of the user who receives this delegation may be required in some cases. We address in this paper these requirements and we propose a formalism to deal with them.
更多
查看译文
关键词
main contribution,access control model,main aim,extended role-based access control,traditional privileges delegation,security policy,important mean,unified model,error-prone task,delegating obligations,role based access control
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要