• DocumentCode
    3119904
  • Title

    Authorization constraint enforcement for information system security

  • Author

    Hewett, Rattikorn ; Kijsanayothin, Phongphun

  • Author_Institution
    Dept. of Comput. Sci., Texas Tech Univ., Abilene, TX
  • fYear
    2008
  • fDate
    12-15 Oct. 2008
  • Firstpage
    3502
  • Lastpage
    3507
  • Abstract
    Managing access authorities is critical to the security of information systems. To prevent fraud or abuse due to conflict of interests, a well-known authorization constraint called separation of duty (SoD) is commonly applied. SoD ensures that no single user receives too many authorities. Enforcement of authorization constraints such as SoD in large organizations can be difficult due to the large number of information system users, the variety of assets involved, and tasks that require roles that may be shared or delegated at multiple levels. Most existing work in this area focuses on specifications of SoD constraints and assumes that constraints can be enforced by logical inference mechanisms at run-time. A drawback of this approach is that when violations occur, finding alternative role activations at run-time may not be feasible. This can result in delays or even failure for critical service transactions. Moreover, logic-based systems are difficult to understand and do not scale easily. This paper presents an algorithmic set-based approach that automatically checks for SoD compliance prior to run-time by searching for a set of valid role activations. The paper discusses details of this approach and illustrates its use in managing access authorizations in a health insurance claim processing system.
  • Keywords
    authorisation; health care; information systems; insurance data processing; logic programming; access authorizations; authorization constraint enforcement; fraud prevention; health insurance claim processing system; information system security; logic-based systems; separation of duty; Access control; Authorization; Computer security; Delay; Inference mechanisms; Information security; Information systems; Management information systems; Protection; Runtime; conflict of interest; information security; policy compliance; role-based access control; separation of duty;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Systems, Man and Cybernetics, 2008. SMC 2008. IEEE International Conference on
  • Conference_Location
    Singapore
  • ISSN
    1062-922X
  • Print_ISBN
    978-1-4244-2383-5
  • Electronic_ISBN
    1062-922X
  • Type

    conf

  • DOI
    10.1109/ICSMC.2008.4811840
  • Filename
    4811840