DocumentCode
1650599
Title
Use Case-Driven Role Based Access Control Security Authorization
Author
Juan, Lin ; Shengbing, Ren ; Ping, Jiang ; Mahammed, Jalloh
Author_Institution
Central South Univ., Changsha
fYear
2007
Firstpage
392
Lastpage
394
Abstract
Role based access control is the most popular access control model recently. In tradition there exists a problem that the role based access control model is not accord well with the system demanding analyse. And it can not guarantee that the security model could meet the users´ demands. This paper introduces a method which describes the design and definition of the role´s rights in system modeling based on use-case driven RBAC. It considers the concept of use case based on RBAC characteristics which combines the use-case model with RBAC model by extending the use case and formalizing the scenario map. Comparing with traditional systems that incorporate use case design model at the end of system design, this method is designed from the beginning of the security design process, so it could identify security problems earlier in the system design to prevent gaps in the security system and meet the least privilege rule.
Keywords
authorisation; case-driven role access control security authorization; least privilege rule; security model; use-case driven RBAC; Access control; Authorization; Centralized control; Design methodology; Electronic mail; Information science; Information security; NIST; Process design; Unified modeling language; Role-Based Access Control Model; Scenario; Security Authorization; Use Case Model;
fLanguage
English
Publisher
ieee
Conference_Titel
Control Conference, 2007. CCC 2007. Chinese
Conference_Location
Hunan
Print_ISBN
978-7-81124-055-9
Electronic_ISBN
978-7-900719-22-5
Type
conf
DOI
10.1109/CHICC.2006.4347306
Filename
4347306
Link To Document