Policy Contexts: Controlling Information Flow in Parameterised RBAC

  • Authors:
  • András Belokosztolszki;David M. Eyers;Ken Moody

  • Affiliations:
  • -;-;-

  • Venue:
  • POLICY '03 Proceedings of the 4th IEEE International Workshop on Policies for Distributed Systems and Networks
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

Many RBAC models have augmented the fundamental requirementof a role abstraction with features such as parameterisedroles and environment-aware policy. This paperexamines the potential for unintentional leakage of informationduring RBAC policy enforcement, either through theexchange of parameters with external services when checkingenvironmental conditions, or through a policy designwhich does not appropriately separate policy subsectionswith different basic purposes. We propose a simple, robustmechanism for handling these problems, and illustrate ourapproach with a current application of our OASIS RBACsystem.