• DocumentCode
    2828830
  • Title

    A user-centered, modular authorization service built on an RBAC foundation

  • Author

    Zurko, Mary Ellen ; Simon, Rich ; Sanfilippo, Tom

  • fYear
    1999
  • fDate
    1999
  • Firstpage
    57
  • Lastpage
    71
  • Abstract
    Psychological acceptability has been mentioned as a requirement for secure systems for as long as least privilege and fail safe defaults, but until now has been all but ignored in the actual design of secure systems. We place this principle at the center of our design for Adage, an authorization service for distributed applications. We employ usability design techniques to specify and test the features of our authorization language and the corresponding administrative GUI. Our testing results reinforce our initial design center and suggest directions for deployment of our authorization services. A modular architecture allows us to experiment with our design during short term integration, and evolve it for longer term exploration. An RBAC foundation enables coherent design of flexible authorization constraints and queries. We discuss lessons learned from the implementation of this service through a planned deployment in a context that must balance new research in risk management with dependencies on legacy services
  • Keywords
    authorisation; bibliographies; distributed processing; graphical user interfaces; high level languages; risk management; user centred design; Adage; RBAC foundation; administrative GUI; authorization language; authorization service; distributed applications; fail safe defaults; legacy services; modular architecture; planned deployment; psychological acceptability; risk management; secure systems; testing results; usability design techniques; user-centered modular authorization service; Access control; Application software; Authorization; Electromagnetic compatibility; Engines; Graphical user interfaces; Iris; Testing; Usability; User centered design;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 1999. Proceedings of the 1999 IEEE Symposium on
  • Conference_Location
    Oakland, CA
  • ISSN
    1081-6011
  • Print_ISBN
    0-7695-0176-1
  • Type

    conf

  • DOI
    10.1109/SECPRI.1999.766718
  • Filename
    766718