A system for visual role-based policy modelling

  • Authors:
  • Massimiliano Giordano;Giuseppe Polese;Giuseppe Scanniello;Genoveffa Tortora

  • Affiliations:
  • Dipartimento di Matematica e Informatica, University of Salerno, Via Ponte Don Melillo, 84084 Fisciano (SA), Italy;Dipartimento di Matematica e Informatica, University of Salerno, Via Ponte Don Melillo, 84084 Fisciano (SA), Italy;Dipartimento di Matematica e Informatica, University of Basilicata, Viale Dell'Ateneo 10, Macchia Romana, 85100 Potenza, Italy;Dipartimento di Matematica e Informatica, University of Salerno, Via Ponte Don Melillo, 84084 Fisciano (SA), Italy

  • Venue:
  • Journal of Visual Languages and Computing
  • Year:
  • 2010

Quantified Score

Hi-index 0.01

Visualization

Abstract

The definition of security policies in information systems and programming applications is often accomplished through traditional low level languages that are difficult to use. This is a remarkable drawback if we consider that security policies are often specified and maintained by top level enterprise managers who would probably prefer to use simplified, metaphor oriented policy management tools. To support all the different kinds of users we propose a suite of visual languages to specify access and security policies according to the role based access control (RBAC) model. Moreover, a system implementing the proposed visual languages is proposed. The system provides a set of tools to enable a user to visually edit security policies and to successively translate them into (eXtensible Access Control Markup Language) code, which can be managed by a Policy Based Management System supporting such policy language. The system and the visual approach have been assessed by means of usability studies and of several case studies. The one presented in this paper regards the configuration of access policies for a multimedia content management platform providing video streaming services also accessible through mobile devices.