Information flow analysis of an RBAC system

  • Authors:
  • Sylvia L. Osborn

  • Affiliations:
  • The University of Western Ontario, London, Ontario, Canada

  • Venue:
  • SACMAT '02 Proceedings of the seventh ACM symposium on Access control models and technologies
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

Role-based access control provides a very flexible set of mechanisms for managing the access control of a complex system with many users, objects and applications. In our previous research, we have shown how, given a role graph and security labels for objects, one can test whether or not the system satisfies properties for lattice-based access control. In this paper we give a general mapping, which takes an arbitrary role graph and produces another graph which shows the information flow that can result from the roles defined in the role graph. An extension builds the information flow graph taking user assignments and sessions into account.