Temporal hierarchies and inheritance semantics for GTRBAC

  • Authors:
  • James B D Joshi;Elisa Bertino;Arif Ghafoor

  • Affiliations:
  • Purdue University, West Lafayette, IN;Universita' di Milano, Milano, Italy;Purdue University, West Lafayette, IN

  • Venue:
  • SACMAT '02 Proceedings of the seventh ACM symposium on Access control models and technologies
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

A Generalized Temporal Role Based Access Control (GTRBAC) model that allows specification of a comprehensive set of temporal constraint for access control has recently been proposed. The model constructs allow one to specify various temporal constraints on role, user-role assignments and role-permission assignments. However, Temporal constraints on role enablings and role activations can have various implications on a role hierarchy. In this paper, we present an analysis of the effects of GTRBAC temporal constraints on a role hierarchy and introduce various kinds of temporal hierarchies. In particular, we show that there are certain distinctions that need to be made in permission inheritance and role activation semantics in order to capture all the effects of GTRBAC constraints such as role enablings and role activations on a role hierarchy.