Title :
Access Control Using Extended Role Graph Corresponding to Organizational Hierarchy
Author :
Lee, Jihyun ; Kang, Sungwon ; Hur, Sunjin
Author_Institution :
Electron. & Telecommun. Res. Inst., Daejeon, South Korea
Abstract :
Changes should continuously occur to enterprise applications whenever organizational structure and business processes are changed. However, the application modification means that the access control modules become more complicated in order to control application users, roles for users, and permissions depending on roles of an organization. This problem was tackled traditionally with the access control mechanism. However, the Role- Based Access Control (RBAC) is recently more actively being researched as a superior mechanism. In this paper, we propose the Extended Role Graph (ERG) approach for assigning and inherit permissions to enhance the RBAC mechanism. The ERG method overcomes the limitations in the existing RBAC and provides a more solid workflow security.
Keywords :
authorisation; commerce; graph theory; business processes; enterprise applications; extended role graph; organizational hierarchy; organizational structure; role-based access control; Authorization; Organizations; Shape; Surgery;
Conference_Titel :
Computers, Networks, Systems and Industrial Engineering (CNSI), 2011 First ACIS/JNU International Conference on
Conference_Location :
Jeju Island
Print_ISBN :
978-1-4577-0180-1
DOI :
10.1109/CNSI.2011.83