Detecting Conflicts in a Role-Based Delegation Model

  • Authors:
  • A. Schaad

  • Affiliations:
  • -

  • Venue:
  • ACSAC '01 Proceedings of the 17th Annual Computer Security Applications Conference
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

The RBAC96 access control model has been the basisfor extensive work on role-based constraint specificationand role-based delegation. However, these practical extensionscan also lead to conflicts at compile and run-time. Wedemonstrate, following a rule-based, declarative approach,how conflicts between specified Separation of Duty constraintsand delegation activities can be detected. This approachalso demonstrates the general suitability of Prologas an executable specification language for the simulationand analysis of role-based systems. Using an extended definitionof a role we show how at least one of the conflicts canbe resolved and discuss the impacts of this extension on thespecified constraints.