Role activation hierarchies

R. Sandhu
{"title":"Role activation hierarchies","authors":"R. Sandhu","doi":"10.1145/286884.286891","DOIUrl":null,"url":null,"abstract":"The concept of a role hierarchy (that is, partial order) is often included in role-based access control (RBAC) models and systems. In current practice the same hierarchy is typically used for two distinct purposes. Members of a senior role in the hierarchy inherit permissions from juniors. We call this the usage (or permissionusage) aspect of role hierarchies. Membership in a senior role also authorizes users to activate junior roles. For purpose of least privilege a user may choose to activate only a junior role on a particular occasion, leaving the senior roles dormant. We call this the activation (or role-activation) aspect of role hierarchies. In this paper we introduce and motivate the idea that there are useful situations where these two hierarchies should not be identical, and the activation hierarchy should extend the inheritance hierarchy. In particular we explore RBAC with respect to read-write access, and its relationship to traditional lattice-based access control or LBAC (also known as mandatory access control). More generally, we consider roles that are required to have dynamic separation of duty.","PeriodicalId":355233,"journal":{"name":"ACM Workshop on Role-Based Access Control","volume":"18 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1998-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"172","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"ACM Workshop on Role-Based Access Control","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/286884.286891","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 172

Abstract

The concept of a role hierarchy (that is, partial order) is often included in role-based access control (RBAC) models and systems. In current practice the same hierarchy is typically used for two distinct purposes. Members of a senior role in the hierarchy inherit permissions from juniors. We call this the usage (or permissionusage) aspect of role hierarchies. Membership in a senior role also authorizes users to activate junior roles. For purpose of least privilege a user may choose to activate only a junior role on a particular occasion, leaving the senior roles dormant. We call this the activation (or role-activation) aspect of role hierarchies. In this paper we introduce and motivate the idea that there are useful situations where these two hierarchies should not be identical, and the activation hierarchy should extend the inheritance hierarchy. In particular we explore RBAC with respect to read-write access, and its relationship to traditional lattice-based access control or LBAC (also known as mandatory access control). More generally, we consider roles that are required to have dynamic separation of duty.
角色激活层次结构
角色层次结构(即部分顺序)的概念通常包含在基于角色的访问控制(RBAC)模型和系统中。在当前的实践中,相同的层次结构通常用于两个不同的目的。层次结构中高级角色的成员继承下级角色的权限。我们称之为角色层次结构的使用(或permissionusage)方面。高级角色中的成员身份还授权用户激活低级角色。出于最低权限的目的,用户可以选择在特定场合只激活初级角色,而不激活高级角色。我们称之为角色层次结构的激活(或角色激活)方面。在本文中,我们引入并激发了这样一个想法:在一些有用的情况下,这两个层次结构不应该相同,激活层次结构应该扩展继承层次结构。我们特别探讨了读写访问方面的RBAC,以及它与传统的基于格的访问控制或LBAC(也称为强制访问控制)的关系。更一般地说,我们考虑需要有动态职责分离的角色。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信