|
ABSTRACT
Access control models have traditionally included mandatory access control (or lattice-based access control) and discretionary access control. Subsequently, role-based access control has been introduced, along with claims that its mechanisms are general enough to simulate the traditional methods. In this paper we provide systematic constructions for various common forms of both of the traditional access control paradigms using the role-based access control (RBAC) models of Sandhu et al., commonly called RBAC96. We see that all of the features of the RBAC96 model are required, and that although for the manatory access control simulation, only one administrative role needs to be assumed, for the discretionary access control simulations, a complex set of administrative roles is required.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
BELL, D. 1987. Secure computer systems: A network interpretation. In Proceedings on 3rd Annual Computer Security Application Conference. 32-39.
|
| |
2
|
CLARK,D.AND WILSON, D. 1987. A comparison of commercial and military computer security policies. In Proceedings of IEEE Symposium on Security and Privacy (Oakland, CA, May). 184-194.
|
 |
3
|
|
| |
4
|
GRAHAM,G.AND DENNING, P. 1972. Protection-principles and practice. In Proceedings on AFIPS Spring Joint Computer Conference. AFIPS Press, Arlington, VA, 417-429.
|
| |
5
|
LAMPSON, B. 1974. Protection. In Proceedings of the 5th Symposium on Information Sciences and Systems (Princeton, NJ, Mar.). 437-443.
|
| |
6
|
LEE, T. 1988. Using mandatory integrity to enforce "commercial" security. In Proceedings of IEEE Symposium on Security and Privacy (Oakland, CA). 140-146.
|
| |
7
|
|
| |
8
|
|
| |
9
|
|
 |
10
|
|
 |
11
|
|
| |
12
|
|
| |
13
|
|
| |
14
|
|
 |
15
|
|
| |
16
|
|
 |
17
|
|
| |
18
|
SANDHU,R.AND SAMARATI, P. 1994. Access control: Principles and practice. IEEE Commun. Mag. 32,9,40-48.
|
| |
19
|
SANDHU,R.S.AND SAMARATI, P. 1997. Authentication, access control and intrusion detection. In The Computer Science and Engineering Handbook, A. B. Tucker, Ed. CRC Press, Inc., Boca Raton, FL, 1929-1948.
|
| |
20
|
SCHOCKLEY, W. 1988. Implementing the Clark/Wilson integrity policy using current technology. In Proceedings of the 11th National Computer Security Conference (NIST-NCSC, Baltimore, Maryland, Oct.17-20). National Institute of Standards and Technology, Gaithersburg, MD, 29-37.
|
CITED BY 60
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Charles E. Phillips, Jr. , T.C. Ting , Steven A. Demurjian, Information sharing and security in dynamic coalitions, Proceedings of the seventh ACM symposium on Access control models and technologies, June 03-04, 2002, Monterey, California, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Rafae Bhatti , James Joshi , Elisa Bertino , Arif Ghafoor, X-GTRBAC admin: a decentralized administration model for enterprise wide access control, Proceedings of the ninth ACM symposium on Access control models and technologies, June 02-04, 2004, Yorktown Heights, New York, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Patrick C. K. Hung , Dickson K. W. Chiu , W. W. Fung , William K. Cheung , Raymond Wong , Samuel P. M. Choi , Eleanna Kafeza , James Kwok , Jousha C. C. Pun , Vivying S. Y. Cheng, Towards end-to-end privacy control in the outsourcing of marketing activities: a web service integration solution, Proceedings of the 7th international conference on Electronic commerce, August 15-17, 2005, Xi'an, China
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Timothy Fraser , David Ferraiolo , Mikel L. Matthews , Casey Schaufler , Stephen Smalley , Robert Watson, Panel: which access control technique will provide the greatest overall benefit, Proceedings of the sixth ACM symposium on Access control models and technologies, p.141-149, May 2001, Chantilly, Virginia, United States
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Taeseong Kim , Christopher D. Cera , William C. Regli , Hyunseung Choo , JungHyun Han, Multi-Level modeling and access control for data sharing in collaborative design, Advanced Engineering Informatics, v.20 n.1, p.47-57, January, 2006
|
REVIEW
"James P. Anderson : Reviewer"
The authors show that a particular set of RBAC models
known as RBAC96 can be used to define a variety of lattice based
access controls (LBAC), an abstraction and generalization of
what is also known as the hierarchical access control model.
more...
|