|
ABSTRACT
Role-based access control (RBAC) models are receiving increasing attention as a generalized approach to access control. Roles may be available to users at certain time periods, and unavailable at others. Moreover, there can be temporal dependencies among roles. To tackle such dynamic aspects, we introduce Temporal-RBAC (TRBAC), an extension of the RBAC model. TRBAC supports periodic role enabling and disabling---possibly with individual exceptions for particular users---and temporal dependencies among such actions, expressed by means of role triggers. Role trigger actions may be either immediately executed, or deferred by an explicitly specified amount of time. Enabling and disabling actions may be given a priority, which is used to solve conflicting actions. A formal semantics for the specification language is provided, and a polynomial safeness check is introduced to reject ambiguous or inconsistent specifications. Finally, a system implementing TRBAC on top of a conventional DBMS is presented.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
|
| |
2
|
ATLURI,V.(ED.) 1999. Proceedings of the Fourth ACM Workshop on Role-Based Access Control (Fairfax, Va.).
|
| |
3
|
|
 |
4
|
|
 |
5
|
|
| |
6
|
|
 |
7
|
|
 |
8
|
|
| |
9
|
GELFOND,M.AND LIFSCHITZ, V. 1988. The stable model semantics for logic programming. In Proceedings of the Fifth ICLP Conference, MIT Press, Cambridge, Mass., 1070-1080.
|
| |
10
|
GULUTZAN,P.AND PELZER, T. 1999. SQL99 Complete, Really. Miller Freeman, Kansas.
|
 |
11
|
|
| |
12
|
|
| |
13
|
|
 |
14
|
|
| |
15
|
|
| |
16
|
|
| |
17
|
LOBO,J.AND RACHID, L. 1994. A semantics for a class of non-deterministic and causal production system programs. J. Autom. Reason. 12, 308-349.
|
| |
18
|
NIEZETTE,M.AND STEVENNE, J. 1992. An efficient symbolic representation of periodic time. In Proceedings of the First International Conference on Information and Knowledge Management.
|
 |
19
|
|
 |
20
|
|
 |
21
|
|
| |
22
|
SANDHU, R. 1991. Separation of duties in computerized information systems. In Database Security IV: Status and Prospects, North Holland, Amsterdam, the Netherlands, 179-189.
|
| |
23
|
SANDHU,R.(ED.) 1995. Proceedings of the First ACM Workshop on Role-Based Access Control (Fairfax, Va.).
|
| |
24
|
|
| |
25
|
SANDHU,R.(ED.) 1997. Proceedings of the Second ACM Workshop on Role-Based Access Control (Fairfax, Va.).
|
| |
26
|
SANDHU,R.(ED.) 1998a. Proceedings of the Third ACM Workshop on Role-Based Access Control (Fairfax, Va.).
|
| |
27
|
SANDHU, R. 1998b. Role-based access control. Advances in Computers, 46, Academic Press.
|
| |
28
|
|
| |
29
|
|
 |
30
|
|
CITED BY 40
|
|
|
Shu-Ching Chen , Mei-Ling Shyu , Na Zhao, SMARXO: towards secured multimedia applications by adopting RBAC, XML and object-relational database, Proceedings of the 12th annual ACM international conference on Multimedia, October 10-16, 2004, New York, NY, USA
|
|
|
|
Marc Wilikens , Simone Feriti , Alberto Sanna , Marcelo Masera, A context-related authorization and access control method based on RBAC:, Proceedings of the seventh ACM symposium on Access control models and technologies, June 03-04, 2002, Monterey, California, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Muhammad Alam , Michael Hafner , Ruth Breu, A constraint based role based access control in the SECTET a model-driven approach, Proceedings of the 2006 International Conference on Privacy, Security and Trust: Bridge the Gap Between PST Technologies and Business Services, October 30-November 01, 2006, Markham, Ontario, Canada
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Radha Jagadeesan , Will Marrero , Corin Pitcher , Vijay Saraswat, Timed constraint programming: a declarative approach to usage control, Proceedings of the 7th ACM SIGPLAN international conference on Principles and practice of declarative programming, p.164-175, July 11-13, 2005, Lisbon, Portugal
|
|
Stere Preda , Frédéric Cuppens , Nora Cuppens-Boulahia , Joaquin G. Alfaro , Laurent Toutain , Yehia Elrakaiby, Semantic context aware security policy deployment, Proceedings of the 4th International Symposium on Information, Computer, and Communications Security, March 10-12, 2009, Sydney, Australia
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Peer to Peer - Readers of this Article have also read:
-
Inferring constraints from multiple snapshots
ACM Transactions on Graphics (TOG)
12, 4
David Kurlander
, Steven Feiner
-
Data structures for quadtree approximation and compression
Communications of the ACM
28, 9
Hanan Samet
-
A hierarchical single-key-lock access control using the Chinese remainder theorem
Proceedings of the 1992 ACM/SIGAPP Symposium on Applied computing
Kim S. Lee
, Huizhu Lu
, D. D. Fisher
-
The GemStone object database management system
Communications of the ACM
34, 10
Paul Butterworth
, Allen Otis
, Jacob Stein
-
Putting innovation to work: adoption strategies for multimedia communication systems
Communications of the ACM
34, 12
Ellen Francik
, Susan Ehrlich Rudman
, Donna Cooper
, Stephen Levine
|