Management advantages of object classification in role-based access control (RBAC)

  • Authors:
  • Mohammad Jafari;Mohammad Fathian

  • Affiliations:
  • Department of Information Technology, Faculty of Industrial Engineering, University of Science and Technology, Narmak, Tehran, Iran;Department of Information Technology, Faculty of Industrial Engineering, University of Science and Technology, Narmak, Tehran, Iran

  • Venue:
  • ASIAN'07 Proceedings of the 12th Asian computing science conference on Advances in computer science: computer and network security
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper investigates the advantages of enabling object classification in role-based access control (RBAC). First, it is shown how the merits of the RBAC models can be ascribed to its using of abstraction and state of dependencies. Following same arguments, it is shown how inclusion of object classification will ameliorate dependencies and abstractions in the model. The discussion contains examining seven criteria to compare object-classification-enabled RBAC with plain RBAC and trivial-permission-assignment models, in order to show the advantages of object classification in a more formal manner. The criteria are: number and complexity of decisions, change management cost, risk of errors, policy portability and reuse, enforcement and compliance, support for traditional information classification policies, and object grouping and management support.