• DocumentCode
    2805320
  • Title

    Three-Layers Role-Based Access Control Framework in Large Financial Web Systems

  • Author

    Wen, Zhicha ; Zhou, Bo ; Wu, Di

  • Author_Institution
    Coll. of Comput. Sci., Zhejiang Univ., Hangzhou, China
  • fYear
    2009
  • fDate
    11-13 Dec. 2009
  • Firstpage
    1
  • Lastpage
    4
  • Abstract
    There are lots of sensitive and confidential data in financial field, such as credit card number, stock number, fund number and so on. Therefore, top level security requirement is always required in financial systems, where a good access control framework is necessary. Traditional role-based access control frameworks lack of control in data access granularity and often slow down the system, even though it provides an efficient access control model which can restrict users´ operation according to their roles. They can hardly meet the requirements in large financial system. This article proposes and implements a Three-Layer Role-based Access Control framework (TL-RBAC) which can perfectly meet the requirements in large financial system. TL-RBAC implements access control in three layers: web pages, operations and data. Coarse-grained access control in web pages layer is used to filter anonymous attacks such as web scan and DoS attacks. Fine-grained access control in operations and data layers guarantee that the user cannot do operations and access data out of his privilege. Performance testing report of the system shows that TL-RBAC meets the performance requirement in terms of system throughput and time per operation.
  • Keywords
    Internet; authorisation; financial data processing; DoS attacks; Web pages layer; Web scan; access control model; anonymous attacks; coarse-grained access control; credit card number; data access granularity; data layers; financial Web system; fine-grained access control; fund number; role-based access control framework; stock number; system throughput; three-layer role-based access control; top level security requirement; Access control; Computer hacking; Computer science; Credit cards; Data security; Educational institutions; Filters; System performance; Throughput; Web pages;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence and Software Engineering, 2009. CiSE 2009. International Conference on
  • Conference_Location
    Wuhan
  • Print_ISBN
    978-1-4244-4507-3
  • Electronic_ISBN
    978-1-4244-4507-3
  • Type

    conf

  • DOI
    10.1109/CISE.2009.5362682
  • Filename
    5362682