ACM Home Page
Please provide us with feedback. Feedback
Role-based authorization constraints specification
Full text PdfPdf (282 KB)
Source ACM Transactions on Information and System Security (TISSEC) archive
Volume 3 ,  Issue 4  (November 2000) table of contents
Pages: 207 - 226  
Year of Publication: 2000
ISSN:1094-9224
Authors
Gail-Joon Ahn  Univ. of North Carolina at Charlotte, NC
Ravi Sandhu  George Mason Univ., Faifax, VA
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 26,   Downloads (12 Months): 184,   Citation Count: 62
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/382912.382913
What is a DOI?

ABSTRACT

Constraints are an important aspect of role-based access control (RBAC) and are often regarded as one of the principal motivations behind RBAC. Although the importance of contraints in RBAC has been recogni zed for a long time, they have not recieved much attention. In this article, we introduce an intuitive formal language for specifying role-based authorization constraints named RCL 2000 including its basic elements, syntax, and semantics. We give soundness and completeness proofs for RCL 2000 relative to a restricted form of first-order predicate logic. Also, we show how previously identified role-based authorization constraints such as separtation of duty (SOD) can be expressed in our language. Moreover, we show there are other significant SOD properties that have not been previously identified in the literature. Our work shows that there are many alternate formulations of even the simplest SOD properties, with varying degree of flexibility and assurance. Our language provides us a rigorous foundation for systematic study of role-based authorization constraints.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
2
3
 
4
 
5
GLIGOR,V.D.,GAVRILA, S., AND FERRAIOLO, D. 1998. On the formal definition of separationof-duty policies and their composition. In Proceedings of the 1998 IEEE Computer Society Symposium on Research in Security and Privacy (Oakland, CA, May). IEEE Computer Society Press, Los Alamitos, CA, 172-183.
6
7
8
 
9
10
11
 
12
 
13
 
14

CITED BY  63

Collaborative Colleagues:
Gail-Joon Ahn: colleagues
Ravi Sandhu: colleagues