DocumentCode :
2289841
Title :
Towards a Group-Based RBAC Model and Decentralized User-Role Administration
Author :
Li, Qi ; Xu, Mingwei ; Zhang, Xinwen
Author_Institution :
Dept. of Comput. Sci., Tsinghua Univ., Beijing
fYear :
2008
fDate :
17-20 June 2008
Firstpage :
441
Lastpage :
446
Abstract :
Role-based Access Control (RBAC) has been widely deployed in many distributed systems in recent years. However, in many large-scale enterprise environments, it is difficult to manage RBAC because of the huge number of users and roles, and complex interrelationships between them. Moreover, with the development of information and communication technologies, many temporal and ad hoc collaborations between groups and departments are emerging, which require dynamic user-role and permission-role assignments. In these scenarios it is infeasible, if not impossible, for few security officers to administrate the assignment for various applications. In this paper, we propose a novel RBAC model for decentralized and distributed systems. As one of the main contributions, we also propose a decentralized administration model to address the management issues in traditional RBAC systems, Our model can be used for group-based applications with dynamic assignments where typically local (group-level) administrators take charge of the dynamic assignments. In this way, many administrative tasks for different applications can spread over many different local administrators, and a fine-grained administration model of RBAC based on the local administration policies is realized. As a proof-of-concept system, we implemented a secure Spread prototype based on our proposed model to show the feasibility in the real applications.
Keywords :
authorisation; distributed processing; communication technology; complex interrelationships; decentralized administration model; decentralized systems; decentralized user-role administration; distributed systems; dynamic assignment; dynamic user-role assignment; group-based RBAC model; information technology; large-scale enterprise environment; permission-role assignment; security; Access control; Authorization; Collaboration; Communications technology; Distributed computing; Environmental management; Information security; Large-scale systems; Prototypes; Videoconference; GB-RBAC; RBAC; Role administration;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Distributed Computing Systems Workshops, 2008. ICDCS '08. 28th International Conference on
Conference_Location :
Beijing
ISSN :
1545-0678
Print_ISBN :
978-0-7695-3173-1
Electronic_ISBN :
1545-0678
Type :
conf
DOI :
10.1109/ICDCS.Workshops.2008.26
Filename :
4577824
Link To Document :
بازگشت