Title :
Use Case-Driven Role Based Access Control Security Authorization
Author :
Juan, Lin ; Shengbing, Ren ; Ping, Jiang ; Mahammed, Jalloh
Author_Institution :
Central South Univ., Changsha
Abstract :
Role based access control is the most popular access control model recently. In tradition there exists a problem that the role based access control model is not accord well with the system demanding analyse. And it can not guarantee that the security model could meet the users´ demands. This paper introduces a method which describes the design and definition of the role´s rights in system modeling based on use-case driven RBAC. It considers the concept of use case based on RBAC characteristics which combines the use-case model with RBAC model by extending the use case and formalizing the scenario map. Comparing with traditional systems that incorporate use case design model at the end of system design, this method is designed from the beginning of the security design process, so it could identify security problems earlier in the system design to prevent gaps in the security system and meet the least privilege rule.
Keywords :
authorisation; case-driven role access control security authorization; least privilege rule; security model; use-case driven RBAC; Access control; Authorization; Centralized control; Design methodology; Electronic mail; Information science; Information security; NIST; Process design; Unified modeling language; Role-Based Access Control Model; Scenario; Security Authorization; Use Case Model;
Conference_Titel :
Control Conference, 2007. CCC 2007. Chinese
Conference_Location :
Hunan
Print_ISBN :
978-7-81124-055-9
Electronic_ISBN :
978-7-900719-22-5
DOI :
10.1109/CHICC.2006.4347306