ACM Home Page
Please provide us with feedback. Feedback
Cooperative role-based administration
Full text PdfPdf (308 KB)
Source Symposium on Access Control Models and Technologies archive
Proceedings of the eighth ACM symposium on Access control models and technologies table of contents
Como, Italy
SESSION: Enterprise Role Administration table of contents
Pages: 21 - 32  
Year of Publication: 2003
ISBN:1-58113-681-1
Authors
Horst F. Wedde  University of Dortmund, Dortmund, Germany
Mario Lischka  University of Dortmund, Dortmund, Germany
Sponsors
ACM: Association for Computing Machinery
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 3,   Downloads (12 Months): 35,   Citation Count: 3
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues   peer to peer  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/775412.775416
What is a DOI?

ABSTRACT

In large organizations the administration of access privileges (such as the assignment of an access right to a user in a particular role) is handled cooperatively through distributed administrators in various different capacities. A quorum may be necessary, or a veto may be possible for such a decision. In this paper we present two major contributions: We develop a Role-Based Access Control (RBAC) approach for specifying distributed administration requirements, and procedures between administrators, or administration teams, extending earlier work on distributed (modular) authorization. While a comprehensive specification in such a language is conceivable it would be quite tedious to evaluate, or analyze, their operational aspects and properties in practice. For this reason we create a new class of extended Petri Nets called Administration Nets such that any RBAC specification of (cooperative) administration requirements (given in terms of predicate logic formulas) can be embedded into an Administration Net. This net behaves within the constraints specified by the logical formulas, and at the same time, it explicitly exhibits all needed operational details such as to allow for an efficient and comprehensive formal analysis of administrative behavior. We introduce the new concepts and illustrate their use in several examples. While Administration Nets are much more refined and (behaviorally) explicit than work flow systems our work provides for a constructive step towards novel work-flow management tools as well.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
W. Aalst. The Application of Petri Nets to Workflow Management. The Journal of Circuits, Systems and Computers, 8(1):21--66, 1998.
2
 
3
 
4
 
5
6
 
7
8
9
10
 
11
 
12
M. Schiffers and H. Wedde. Analyzing program solutions of coordination problems by cp-nets. In A. Mazurkiewicz, editor, Proceedings of the 7th Symposium on Mathematical Foundations of Computer Science, volume~64 of Lecture Notes in Computer Science, pages 416--422. Springer Verlag, Zakopane, Poland, 1978.
 
13
R. Valk. Infinitive behaviour of petri nets. Theoretical Computer Science, 25:311--341, 1983.
14
 
15
H. F. Wedde and M. Lischka. Composing Heterogenous Access Policies between Organizations. In Proceedings of the IADIS International Conference e-Society 2003, Lisbon/ Portuagal, June, 3-6 2003. International Association for Development of the Information Society. to be published.


Collaborative Colleagues:
Horst F. Wedde: colleagues
Mario Lischka: colleagues

Peer to Peer - Readers of this Article have also read: