{"title":"Exploring User-to-Role Delegation in Role-Based Access Control","authors":"Wei Qiu, C. Adams","doi":"10.1109/WCMEB.2007.47","DOIUrl":null,"url":null,"abstract":"Enterprises must have business security solutions that provide detection and enforcement at every point of network access. Role-based access control (RBAC) formulates that access decisions are based on the roles that individual users have as members of a system. In RBAC, there are role hierarchies in which a senior role inherits the permissions of a junior role. In order to allow a junior role to perform one or more tasks of a senior role, various delegation models have been proposed in the literature. This paper presents a new role-based delegation model called user-to-role delegation model (URDM), which supports multiple delegation, role hierarchy, and single-step delegation. Four situations are analyzed when URDM runs a multiple delegation process. A Web-based system called university delegation management system (UDMS) is designed and implemented to verify the core functionality of URDM within the first situation.","PeriodicalId":140908,"journal":{"name":"Eighth World Congress on the Management of eBusiness (WCMeB 2007)","volume":"19 11","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-07-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Eighth World Congress on the Management of eBusiness (WCMeB 2007)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WCMEB.2007.47","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5
Abstract
Enterprises must have business security solutions that provide detection and enforcement at every point of network access. Role-based access control (RBAC) formulates that access decisions are based on the roles that individual users have as members of a system. In RBAC, there are role hierarchies in which a senior role inherits the permissions of a junior role. In order to allow a junior role to perform one or more tasks of a senior role, various delegation models have been proposed in the literature. This paper presents a new role-based delegation model called user-to-role delegation model (URDM), which supports multiple delegation, role hierarchy, and single-step delegation. Four situations are analyzed when URDM runs a multiple delegation process. A Web-based system called university delegation management system (UDMS) is designed and implemented to verify the core functionality of URDM within the first situation.