Engineering of Role/Permission Assignments

  • Authors:
  • P. Epstein;R. Sandhu

  • Affiliations:
  • -;-

  • Venue:
  • ACSAC '01 Proceedings of the 17th Annual Computer Security Applications Conference
  • Year:
  • 2001

Quantified Score

Hi-index 0.01

Visualization

Abstract

In this paper, we develop a model forengineering role-permission assignment. Ourmodel builds upon the well-known RBAC96model [SCFY96]. Assigning permissions toroles is considered too complex an activity toaccomplish directly. Instead we advocatebreaking down this process into a number ofsteps. We specifically introduce the concept ofJobs, Work-patterns, and Tasks to facilitate role-permissionassignment into a series of smallersteps. We describe methodologies for using thismodel in two different ways. In a top-downapproach, roles are decomposed intopermissions, whereas in a bottom-up approach,permissions are aggregated into roles.