Revocation Schemes for Delegation Licences

  • Authors:
  • Meriam Ben-Ghorbel-Talbi;Frédéric Cuppens;Nora Cuppens-Boulahia;Adel Bouhoula

  • Affiliations:
  • Institut TELECOM/TELECOM Bretagne, Cesson Sévigné Cedex, France 35576 and SUP'COM Tunis, Ariana, Tunisie 2083;Institut TELECOM/TELECOM Bretagne, Cesson Sévigné Cedex, France 35576;Institut TELECOM/TELECOM Bretagne, Cesson Sévigné Cedex, France 35576;SUP'COM Tunis, Ariana, Tunisie 2083

  • Venue:
  • ICICS '08 Proceedings of the 10th International Conference on Information and Communications Security
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

The paper presents revocation schemes in role-based access control models. We are particularly interested in two key issues: how to perform revocation and how to manage the revocation policy. We show how to deal with these two aspects in the delegation model based on the OrBAC formalism and its administration licence concept. This model provides means to manage several delegation types, such as the delegation or transfer of permissions and roles, multi-step delegation and temporary delegation. We state formally in this paper how to manage the revocation of these delegation schemes. Our model supports a wide spectrum of revocation dimensions such as propagation, dominance, dependency, automatic/user revocation, transfer revocation and role/permission revocation.