Using description logic to determine seniority among RB-RBAC authorization rules

  • Authors:
  • Qi Xie;Dayou Liu;Haibo Yu

  • Affiliations:
  • College of Computer Science and Technology, Jilin University, Changchun, P.R. China;College of Computer Science and Technology, Jilin University, Changchun, P.R. China;College of Computer Science and Technology, Jilin University, Changchun, P.R. China

  • Venue:
  • RSKT'06 Proceedings of the First international conference on Rough Sets and Knowledge Technology
  • Year:
  • 2006

Quantified Score

Hi-index 0.02

Visualization

Abstract

Rule-Based RBAC (RB-RBAC) provides the mechanism to dynamically assign users to roles based on authorization rules defined by security policy. In RB-RBAC, seniority levels of rules are also introduced to express domination relationship among rules. Hence, relations among attribute expressions may be quite complex and security officers may perform incorrect or unintended assignments if they are not aware of such relations behind authorization rules. We proposed a formalization of RB-RBAC by description logic. A seniority relation determination method is developed based on description logic reasoning services. This method can find out seniority relations efficiently even for rules without identical syntax structures