DocumentCode :
2159345
Title :
Active Authorization Rules for Enforcing Role-Based Access Control and its Extensions
Author :
Adaikkalavan, Raman ; Chakravarthy, Sharma
Author_Institution :
The University of Texas at Arlington
fYear :
2005
fDate :
05-08 April 2005
Firstpage :
1197
Lastpage :
1197
Abstract :
Dynamically monitoring the state changes of an underlying system, detecting and reacting to changes without delay are crucial for the success of any access control enforcement mechanism. With their inherent nature, active (Event- Condition-Action or ECA) rules are prospective candidates to carry out change detection and to provide access control. Current systems or models do not provide a flexible mechanism for enforcing Role-Based Access Control (RBAC) standard and its extensions in a seamless way, and do not adapt to policy or role structure changes in enterprises, which are indispensable to make RBAC usable in diverse domains. In this paper we will show how On-When-Then-Else authorization rules (or enhanced ECA rules) are used for enforcing RBAC standard and its extensions such as generalized temporal RBAC, control flow dependency constraints, privacy-aware RBAC, and so forth in a seamless way. Furthermore, these rules also provide active security. Large enterprises have hundreds of roles, which requires thousands of rules for providing access control, and generating these rules manually is error-prone and a cognitive-burden for non-computer specialists. Thus, in this paper, we will discuss briefly how these authorization rules can be automatically (or semi-automatically) generated from high level specifications of enterprise access control policies. We will also discuss the implementation using Sentinel+, an active object oriented system.
Keywords :
Access control; Authorization; Computer science; Computerized monitoring; Delay; Error correction; Information technology; Object oriented modeling; Privacy; Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Data Engineering Workshops, 2005. 21st International Conference on
Print_ISBN :
0-7695-2657-8
Type :
conf
DOI :
10.1109/ICDE.2005.179
Filename :
1647810
Link To Document :
بازگشت