FORBAC: a flexible organisation and role-based access control model for secure information systems

  • Authors:
  • Oumaima Saidani;Selmin Nurcan

  • Affiliations:
  • Centre de Recherche en Informatique, Université Paris 1 Panthéon – Sorbonne, Paris, France;Centre de Recherche en Informatique, Université Paris 1 Panthéon – Sorbonne, Paris, France

  • Venue:
  • ADVIS'06 Proceedings of the 4th international conference on Advances in Information Systems
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security of information systems is an increasingly critical issue. Access control is a crucial technique ensuring security. It should be based on an effective model. Even if some approaches have already been proposed, a comprehensive model, flexible enough to cope with real organizations, is still missing. This paper proposes a new access control model, FORBAC, which deals with the following issues: The first one is the adaptability to various kinds of organization. The second one concerns increasing flexibility and reducing errors and management cost, this is done by introducing a set of components which allow fine-grained and multi-level permission assignment. The paper introduces a framework for evaluating the proposed approach with respect to other related research through views, facets and criteria.