Research on Description Logic Based Conflict Detection Methods for RB-RBAC Model

  • Authors:
  • Haibo Yu;Qi Xie;Haiyan Che

  • Affiliations:
  • College of Computer Science and Technology, Jilin University, Changchun 130012, China;College of Computer Science and Technology, Jilin University, Changchun 130012, China;College of Computer Science and Technology, Jilin University, Changchun 130012, China

  • Venue:
  • Proceedings of the 2006 conference on Advances in Intelligent IT: Active Media Technology 2006
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

The RB-RBAC family introduces negative authorization, represented by negative roles, which may bring conflict, and conflict detection and resolution become an import work in RB-RBAC policy management. We proposed a formalization of RB-RBAC model by description logic and developed conflict detection methods based on description logic reasoning service. Conflicts can be detected when all authorization rules have been defined, and a revised detection method is also given to improve the system efficiency when dynamically adding new authorization rule to system. Conflicts among related rules and among unrelated rules can be distinguished by these methods. We also demonstrate a simple method to resolve conflict.