Title :
Towards dynamically administered role-based access control
Author :
Mattas, Andreas K. ; Mavridis, Ioannis K. ; Pangalos, George I.
Author_Institution :
Aristotle Univ. of Thessaloniki, Greece
Abstract :
In digital business, the need for efficient frameworks to address the multifaceted security issues related to Web-based applications, has led to efforts towards the development of dynamically administered access control systems that implement robust access control models, to allow controlled access of information based on content or context of processing, and secure interoperation in a dynamic distributed enterprise environment. Pure RBAC seems to be suitable for function-oriented organization structures usually used in relatively stable environments. On the other hand, TBAC and TMAC provide a complementary support in environments that are based on process-oriented organization structures. However, current organizational alternatives lead to the combination of the above approaches, in the form of a matrix organization structure that maximizes the advantages of functional and process-oriented structures and introduces the need for new access control administration paradigms. In this paper, we discuss our approach for dynamically administered role-based access control, which covers the need-to-know requirements of users and missions are involved with, and provides tight and just-in-time access control without sacrificing operability and simplicity of administration.
Keywords :
Internet; authorisation; Web-based applications; digital business; dynamic administration; dynamically administered role-based access control; function-oriented organization structures; matrix organization structure; process-oriented structures; robust access control models; security services; task-based authorization controls; team-based access control; user requirements; Access control; Authorization; Centralized control; Conferences; Context modeling; Information security; Monitoring; Public key; Robust control; Web and internet services;
Conference_Titel :
Database and Expert Systems Applications, 2003. Proceedings. 14th International Workshop on
Print_ISBN :
0-7695-1993-8
DOI :
10.1109/DEXA.2003.1232072