DocumentCode :
2081547
Title :
Towards dynamically administered role-based access control
Author :
Mattas, Andreas K. ; Mavridis, Ioannis K. ; Pangalos, George I.
Author_Institution :
Aristotle Univ. of Thessaloniki, Greece
fYear :
2003
fDate :
1-5 Sept. 2003
Firstpage :
494
Lastpage :
498
Abstract :
In digital business, the need for efficient frameworks to address the multifaceted security issues related to Web-based applications, has led to efforts towards the development of dynamically administered access control systems that implement robust access control models, to allow controlled access of information based on content or context of processing, and secure interoperation in a dynamic distributed enterprise environment. Pure RBAC seems to be suitable for function-oriented organization structures usually used in relatively stable environments. On the other hand, TBAC and TMAC provide a complementary support in environments that are based on process-oriented organization structures. However, current organizational alternatives lead to the combination of the above approaches, in the form of a matrix organization structure that maximizes the advantages of functional and process-oriented structures and introduces the need for new access control administration paradigms. In this paper, we discuss our approach for dynamically administered role-based access control, which covers the need-to-know requirements of users and missions are involved with, and provides tight and just-in-time access control without sacrificing operability and simplicity of administration.
Keywords :
Internet; authorisation; Web-based applications; digital business; dynamic administration; dynamically administered role-based access control; function-oriented organization structures; matrix organization structure; process-oriented structures; robust access control models; security services; task-based authorization controls; team-based access control; user requirements; Access control; Authorization; Centralized control; Conferences; Context modeling; Information security; Monitoring; Public key; Robust control; Web and internet services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Database and Expert Systems Applications, 2003. Proceedings. 14th International Workshop on
ISSN :
1529-4188
Print_ISBN :
0-7695-1993-8
Type :
conf
DOI :
10.1109/DEXA.2003.1232072
Filename :
1232072
Link To Document :
بازگشت