DocumentCode
2190704
Title
Constraints for Permission-Based Delegations
Author
Shang, Qinghua ; Wang, Xingang
Author_Institution
Nat. Eng. Res. Center of Fundamental Software, Chinese Acad. of Sci., Beijing
fYear
2008
fDate
8-11 July 2008
Firstpage
216
Lastpage
223
Abstract
Permission-Based Delegation Model (PBDM) is a flexible model for delegation of authority in RBAC. It supports permission level delegation through temporary delegation roles. Multi-step delegation is also supported. However, constraints for PBDM have not been investigated in the literature, and it is not secure for a system to employ PBDM without constraints considered. We present a Constraints model for user-user Permission-Based Delegation (CPBD) to secure such systems. Delegation roles bring violation of the security based on the constraints specified on regular roles. In CPBD, these constraints are extended to involve delegation roles by the new concept of source regular role, and this extension ensures the security based on constrains. Authorization constraints on delegation roles are also considered to satisfy secure requirements of users. For security administrators to obtain more control of delegations, constraints on permission-based delegation itself are provided, in particular, maximum delegation depth and maximum delegation range.
Keywords
authorisation; authority delegation; authorization constraint; maximum delegation depth; maximum delegation range; permission-based delegation model; role based access control; security administrator; Constraints; Permission-Based Delegation Model (PBDM); RBAC;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer and Information Technology Workshops, 2008. CIT Workshops 2008. IEEE 8th International Conference on
Conference_Location
Sydney, QLD
Print_ISBN
978-0-7695-3242-4
Electronic_ISBN
978-0-7695-3239-1
Type
conf
DOI
10.1109/CIT.2008.Workshops.75
Filename
4568506
Link To Document