Design of a Role-Based Trust-Management Framework

  • Authors:
  • Ninghui Li;John C. Mitchell;William H. Winsborough

  • Affiliations:
  • -;-;-

  • Venue:
  • SP '02 Proceedings of the 2002 IEEE Symposium on Security and Privacy
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

We introduce the RT framework, a family of Role-based Trust-managementlanguages for representing policies and credentials in distributedauthorization. RT combines the strengths of role-based access controland trust-management systems and is especially suitable forattribute-based access control. Using a few simple credential forms, RTprovides localized authority over roles, delegation in role definition,linked roles, and parameterized roles. RT also introduces manifoldroles, which can be used to express threshold and separation-of-dutypolicies, and delegation of role activations. We formally define thesemantics of credentials in the RT framework by presenting a translationfrom credentials to Datalog rules.This translation also shows thatthis semantics is algorithmically tractable.