| Observations on the role life-cycle in the context of enterprise security management |
| Full text |
Pdf
(179 KB)
|
| Source
|
Symposium on Access Control Models and Technologies
archive
Proceedings of the seventh ACM symposium on Access control models and technologies
table of contents
Monterey, California, USA
SESSION: Role Engineering
table of contents
Pages: 43 - 51
Year of Publication: 2002
ISBN:1-58113-496-7
|
|
Authors
|
|
Axel Kern
|
Hermann-Heinrich-Gossen-Str. 3, 50858 Cologne, Germany
|
|
Martin Kuhlmann
|
Hermann-Heinrich-Gossen-Str. 3, 50858 Cologne, Germany
|
|
Andreas Schaad
|
University of York, York, YO10 5DD, UK
|
|
Jonathan Moffett
|
University of York, York, YO10 5DD, UK
|
|
| Sponsor |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 10, Downloads (12 Months): 109, Citation Count: 17
|
|
|
ABSTRACT
Roles are a powerful and policy neutral concept for facilitating distributed systems management and enforcing access control. Models which are now subject to becoming a standard have been proposed and much work on extensions to these models has been done over the last years as documented in the recent RBAC/SACMAT workshops. When looking at these extensions we can often observe that they concentrate on a particular stage in the life of a role. We investigate how these extensions fit into a more general theoretical framework in order to give practitioners a starting point from which to develop role-based systems. We believe that the life-cycle of a role could be seen as the basis for such a framework and we provide an initial discussion on such a role life-cycle, based on our experiences and observations in enterprise security management. We propose a life-cycle model that is based on an iterative-incremental process similar to those found in the area of software development.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Biddle B. and E. Thomas, Role Theory: Concepts and Research. New York: Robert E. Krieger Publishing Company, 1979.
|
| |
2
|
Ferraiolo D. and R. Kuhn, "Role-Based Access Control." presented at 15th NCSC National Computer Security Conference, Baltimore, 1992.
|
 |
3
|
|
| |
4
|
|
| |
5
|
Lupu E., "A Role-Based Framework for Distributed Systems Management." PhD Thesis: Department of Computing. London, Imperial College, 1998.
|
 |
6
|
|
 |
7
|
|
| |
8
|
|
 |
9
|
|
 |
10
|
|
| |
11
|
|
| |
12
|
|
| |
13
|
|
| |
14
|
|
| |
15
|
Balzert H., "Lehrbuch der Software-Technik II", Spektrum Akademischer Verlag, Heidelberg/Berlin, 1998.
|
 |
16
|
|
 |
17
|
|
 |
18
|
Christos K. Georgiadis , Ioannis Mavridis , George Pangalos , Roshan K. Thomas, Flexible team-based access control using contexts, Proceedings of the sixth ACM symposium on Access control models and technologies, p.21-27, May 2001, Chantilly, Virginia, United States
[doi> 10.1145/373256.373259]
|
| |
19
|
|
 |
20
|
|
CITED BY 17
|
|
|
|
|
|
|
|
|
|
|
Axel Kern , Martin Kuhlmann , Rainer Kuropka , Andreas Ruthert, A meta model for authorisations in application security systems and their integration into RBAC administration, Proceedings of the ninth ACM symposium on Access control models and technologies, June 02-04, 2004, Yorktown Heights, New York, USA
|
|
|
Joon S. Park , Keith P. Costello , Teresa M. Neven , Josh A. Diosomito, A composite rbac approach for large, complex organizations, Proceedings of the ninth ACM symposium on Access control models and technologies, June 02-04, 2004, Yorktown Heights, New York, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Jaideep Vaidya , Vijayalakshmi Atluri , Qi Guo , Nabil Adam, Migrating to optimal RBAC with minimal perturbation, Proceedings of the 13th ACM symposium on Access control models and technologies, June 11-13, 2008, Estes Park, CO, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|