首页> 外文期刊>Information systems frontiers >A role-involved purpose-based access control model
【24h】

A role-involved purpose-based access control model

机译:基于角色的基于目的的访问控制模型

获取原文
获取原文并翻译 | 示例
           

摘要

This paper presents a role-involved purpose-based access control (RPAC) model, where a conditional purpose is defined as the intention of data accesses or usages under certain conditions. RPAC allows users using some data for a certain purpose with Conditions (For instance, Tony agrees that his income information can be used for marketing purposes by removing his name). The structure of RPAC model is investigated after defining access purposes, intended purposes and conditional purposes. An algorithm is developed with role-based access control (RBAC) to achieve the compliance computation between access purposes (related to data access) and intended purposes (related to data objects). Access purpose authorization and authentication in the RPAC model are studied with the hierarchical purpose structure. According to the model, more information from data providers can be extracted while at the same time assuring privacy that maximizes the usability of consumers' data. It extends role-based access control models to a further coverage of privacy preservation in database management systems by adopting purposes and conditional intended purposes and to achieve a fine-grained access control. The work in this paper helps enterprises to circulate a clear privacy promise, and to collect and manage user preferences and consent.
机译:本文提出了一个基于角色的基于目的的访问控制(RPAC)模型,其中有条件的目的被定义为在特定条件下数据访问或使用的意图。 RPAC允许用户通过条件将某些数据用于特定目的(例如,托尼同意删除其姓名可以将其收入信息用于营销目的)。在定义访问目的,预期目的和条件目的之后,将对RPAC模型的结构进行研究。使用基于角色的访问控制(RBAC)开发了一种算法,以实现访问目的(与数据访问有关)和预期目的(与数据对象有关)之间的符合性计算。利用分层目的结构研究了RPAC模型中的访问目的授权和认证。根据该模型,可以提取来自数据提供者的更多信息,同时确保最大程度提高消费者数据可用性的隐私性。它通过采用目的和有条件的预期目的并实现细粒度的访问控制,将基于角色的访问控制模型扩展到数据库管理系统中隐私保护的进一步覆盖。本文的工作可帮助企业发布明确的隐私承诺,并收集和管理用户的偏好和同意。

著录项

  • 来源
    《Information systems frontiers》 |2012年第3期|p.809-822|共14页
  • 作者单位

    Department of Mathematics & Computing,University of Southern Queensland, Toowoomba,QLD 4350, Australia;

    Department of Mathematics & Computing,University of Southern Queensland, Toowoomba,QLD 4350, Australia;

    Department of Computer Science and CERIAS,Purdue University, West Lafayette, Indiana, USA;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    access control; conditional purpose; privacy;

    机译:访问控制;有条件的目的隐私;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号