DocumentCode
3281414
Title
Activities and Event-Driven-Based Role Engineering
Author
Mei-Yu Wu
Author_Institution
Dept. of Inf. Manage., Chung Hua Univ., Hsinchu, Taiwan
fYear
2012
fDate
25-28 Aug. 2012
Firstpage
550
Lastpage
553
Abstract
Many companies adopt authorization management to authorize the appropriate permission for users to operate their resources. After role-based access control (RBAC) is proposed and accepted, companies adopt a role, i.e. job position, to achieve authorization management. Although RBAC has become the preferred approach to managing access control, role engineering is an important process to go through before using RBAC. Role engineering is the process of defining roles and related information as they pertain to the user´s functional use. Role engineering is a critical success factor in implementing RBAC. This study proposes activities and event-driven-based role engineering. An event is a routine task, and activities are triggered by events. Roles are created by many overlapping events. Among the roles, events and activities form many to many relationships. Our approach adopts the relationships to define the roles and assign permissions to them. The proposed approach is suitable for organizations attempting to achieve refined role-permission planning, no matter whether or not they are using RBAC.
Keywords
authorisation; RBAC; authorization management; critical success factor; event-driven-based role engineering; role-based access control; role-permission planning; routine task; Aggregates; Authorization; Mathematical model; Organizations; Permission; Activity; Event-Driven; RBAC; Role Engineering;
fLanguage
English
Publisher
ieee
Conference_Titel
Genetic and Evolutionary Computing (ICGEC), 2012 Sixth International Conference on
Conference_Location
Kitakushu
Print_ISBN
978-1-4673-2138-9
Type
conf
DOI
10.1109/ICGEC.2012.40
Filename
6456900
Link To Document