首页> 外文期刊>IEEE Transactions on Knowledge and Data Engineering >A generalized temporal role-based access control model
【24h】

A generalized temporal role-based access control model

机译:基于时间的通用角色访问控制模型

获取原文
获取原文并翻译 | 示例

摘要

Role-based access control (RBAC) models have generated a great interest in the security community as a powerful and generalized approach to security management. In many practical scenarios, users may be restricted to assume roles only at predefined time periods. Furthermore, roles may only be invoked on prespecified intervals of time depending upon when certain actions are permitted. To capture such dynamic aspects of a role, a temporal RBAC (TRBAC) model has been recently proposed. However, the TRBAC model addresses the role enabling constraints only. In This work, we propose a generalized temporal role-based access control (GTRBAC) model capable of expressing a wider range of temporal constraints. In particular, the model allows expressing periodic as well as duration constraints on roles, user-role assignments, and role-permission assignments. In an interval, activation of a role can further be restricted as a result of numerous activation constraints including cardinality constraints and maximum active duration constraints. The GTRBAC model extends the syntactic structure of the TRBAC model and its event and trigger expressions subsume those of TRBAC. Furthermore, GTRBAC allows expressing role hierarchies and separation of duty (SoD) constraints for specifying fine-grained temporal semantics.
机译:基于角色的访问控制(RBAC)模型作为一种强大而通用的安全管理方法,已经引起了安全界的极大兴趣。在许多实际情况下,可能会限制用户仅在预定义的时间段内担任角色。此外,取决于何时允许某些动作,只能在预定的时间间隔内调用角色。为了捕获角色的这种动态方面,最近提出了时间RBAC(TRBAC)模型。但是,TRBAC模型仅解决启用约束的角色。在这项工作中,我们提出了一种通用的基于时间角色的访问控制(GTRBAC)模型,该模型能够表达更广泛的时间约束。特别地,该模型允许表达对角色,用户角色分配和角色权限分配的周期性和持续时间约束。在一个间隔中,由于众多激活约束(包括基数约束和最大激活持续时间约束),可以进一步限制角色的激活。 GTRBAC模型扩展了TRBAC模型的语法结构,并且其事件和触发器表达式包含了TRBAC的语法结构。此外,GTRBAC允许表达角色层次结构和职责分离(SoD)约束,用于指定细粒度的时间语义。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号