Towards an approach for weaving Open Digital Rights Language into Role-Based Access Control

Aisha Alshamsi, Z. Maamar, M. Kuhail
{"title":"Towards an approach for weaving Open Digital Rights Language into Role-Based Access Control","authors":"Aisha Alshamsi, Z. Maamar, M. Kuhail","doi":"10.1109/ITIKD56332.2023.10100036","DOIUrl":null,"url":null,"abstract":"Establishing an adequate and flexible access control over assets in an organization is one of the main pillars of a successful information and technology security-strategy. To ensure efficient use of these assets in terms of availability, safety, and confidentiality, organizations roll out different strategies and adopt different techniques. These strategies and techniques could be based on roles to set access controls (Role-Based Access Control). Despite its popularity, there is an increasing interest in addressing RBAC's limitations with focus on how to enforce an adequate level of access control over the available resources and how to define a flexible control over these resources so that accessibility and authenticity are achieved at the right time and right place. This paper addresses some of these limitations by adopting the Open Digital Rights Language (ODRL) to express who can do what, where, when, and how. ODRL is a policy language that offers flexible control over digital content. By weaving ODRL into RBAC, this paper illustrates how to specify what users are allowed, not allowed, and must be allowed to do through a set of constrained rules specialized into permissions, prohibitions, and duties.","PeriodicalId":283631,"journal":{"name":"2023 International Conference on IT Innovation and Knowledge Discovery (ITIKD)","volume":"126 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-03-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 International Conference on IT Innovation and Knowledge Discovery (ITIKD)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ITIKD56332.2023.10100036","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Establishing an adequate and flexible access control over assets in an organization is one of the main pillars of a successful information and technology security-strategy. To ensure efficient use of these assets in terms of availability, safety, and confidentiality, organizations roll out different strategies and adopt different techniques. These strategies and techniques could be based on roles to set access controls (Role-Based Access Control). Despite its popularity, there is an increasing interest in addressing RBAC's limitations with focus on how to enforce an adequate level of access control over the available resources and how to define a flexible control over these resources so that accessibility and authenticity are achieved at the right time and right place. This paper addresses some of these limitations by adopting the Open Digital Rights Language (ODRL) to express who can do what, where, when, and how. ODRL is a policy language that offers flexible control over digital content. By weaving ODRL into RBAC, this paper illustrates how to specify what users are allowed, not allowed, and must be allowed to do through a set of constrained rules specialized into permissions, prohibitions, and duties.
一种将开放数字权利语言编织到基于角色的访问控制中的方法
对组织中的资产建立充分而灵活的访问控制是成功的信息和技术安全策略的主要支柱之一。为了确保在可用性、安全性和机密性方面有效地使用这些资产,组织推出了不同的策略并采用了不同的技术。这些策略和技术可以基于角色来设置访问控制(基于角色的访问控制)。尽管RBAC很流行,但人们越来越关注如何对可用资源实施适当级别的访问控制,以及如何定义对这些资源的灵活控制,以便在正确的时间和正确的位置实现可访问性和真实性。本文通过采用开放数字权利语言(ODRL)来表达谁可以做什么、在哪里、何时以及如何做,从而解决了其中的一些限制。ODRL是一种策略语言,提供对数字内容的灵活控制。通过将ODRL编织到RBAC中,本文说明了如何通过一组专门用于权限、禁止和职责的约束规则来指定允许、不允许和必须允许用户做什么。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信