|
ABSTRACT
Role-based access control (RBAC) models are receiving increasing attention as a generalized approach to access control. Roles may be available to users at certain time periods, and unavailable at others. Moreover, there can be temporal dependencies among roles. To tackle such dynamic aspects, we introduce Temporal-RBAC (TRBAC), an extension of the RBAC model. TRBAC supports periodic role enabling and disabling---possibly with individual exceptions for particular users---and temporal dependencies among such actions, expressed by means of role triggers. Role trigger actions may be either immediately executed, or deferred by an explicitly specified amount of time. Enabling and disabling actions may be given a priority, which is used to solve conflicting actions. A formal semantics for the specification language is provided, and a polynomial safeness check is introduced to reject ambiguous or inconsistent specifications. Finally, a system implementing TRBAC on top of a conventional DBMS is presented.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
|
| |
2
|
ATLURI,V.(ED.) 1999. Proceedings of the Fourth ACM Workshop on Role-Based Access Control (Fairfax, Va.).
|
| |
3
|
|
 |
4
|
|
 |
5
|
|
| |
6
|
|
 |
7
|
|
 |
8
|
|
| |
9
|
GELFOND,M.AND LIFSCHITZ, V. 1988. The stable model semantics for logic programming. In Proceedings of the Fifth ICLP Conference, MIT Press, Cambridge, Mass., 1070-1080.
|
| |
10
|
GULUTZAN,P.AND PELZER, T. 1999. SQL99 Complete, Really. Miller Freeman, Kansas.
|
 |
11
|
|
| |
12
|
|
| |
13
|
|
 |
14
|
|
| |
15
|
|
| |
16
|
|
| |
17
|
LOBO,J.AND RACHID, L. 1994. A semantics for a class of non-deterministic and causal production system programs. J. Autom. Reason. 12, 308-349.
|
| |
18
|
NIEZETTE,M.AND STEVENNE, J. 1992. An efficient symbolic representation of periodic time. In Proceedings of the First International Conference on Information and Knowledge Management.
|
 |
19
|
|
 |
20
|
|
 |
21
|
|
| |
22
|
SANDHU, R. 1991. Separation of duties in computerized information systems. In Database Security IV: Status and Prospects, North Holland, Amsterdam, the Netherlands, 179-189.
|
| |
23
|
SANDHU,R.(ED.) 1995. Proceedings of the First ACM Workshop on Role-Based Access Control (Fairfax, Va.).
|
| |
24
|
|
| |
25
|
SANDHU,R.(ED.) 1997. Proceedings of the Second ACM Workshop on Role-Based Access Control (Fairfax, Va.).
|
| |
26
|
SANDHU,R.(ED.) 1998a. Proceedings of the Third ACM Workshop on Role-Based Access Control (Fairfax, Va.).
|
| |
27
|
SANDHU, R. 1998b. Role-based access control. Advances in Computers, 46, Academic Press.
|
| |
28
|
|
| |
29
|
|
 |
30
|
|
CITED BY 43
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Shu-Ching Chen , Mei-Ling Shyu , Na Zhao, SMARXO: towards secured multimedia applications by adopting RBAC, XML and object-relational database, Proceedings of the 12th annual ACM international conference on Multimedia, October 10-16, 2004, New York, NY, USA
|
|
|
|
|
|
Marc Wilikens , Simone Feriti , Alberto Sanna , Marcelo Masera, A context-related authorization and access control method based on RBAC:, Proceedings of the seventh ACM symposium on Access control models and technologies, June 03-04, 2002, Monterey, California, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Radha Jagadeesan , Will Marrero , Corin Pitcher , Vijay Saraswat, Timed constraint programming: a declarative approach to usage control, Proceedings of the 7th ACM SIGPLAN international conference on Principles and practice of declarative programming, p.164-175, July 11-13, 2005, Lisbon, Portugal
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Muhammad Alam , Michael Hafner , Ruth Breu, A constraint based role based access control in the SECTET a model-driven approach, Proceedings of the 2006 International Conference on Privacy, Security and Trust: Bridge the Gap Between PST Technologies and Business Services, October 30-November 01, 2006, Markham, Ontario, Canada
|
|
|
|
|
|
Stere Preda , Frédéric Cuppens , Nora Cuppens-Boulahia , Joaquin G. Alfaro , Laurent Toutain , Yehia Elrakaiby, Semantic context aware security policy deployment, Proceedings of the 4th International Symposium on Information, Computer, and Communications Security, March 10-12, 2009, Sydney, Australia
|
|
|
|
|
|
|
|
|
|
|