Specification and Classification of Role-based Authorization Policies

  • Authors:
  • Gail-Joon Ahn

  • Affiliations:
  • -

  • Venue:
  • WETICE '03 Proceedings of the Twelfth International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

Constraints are an important aspect of role-basedaccess control (RBAC). Although the importance ofconstraints in RBAC has been recognized for a longtime, they have not received much attention. In thispaper we classify RBAC constraints into two majorclasses called prohibition constraints and obligationconstraints. To specify these constraints, we utilize aformal language, named RCL2000. In this paper weshow that prohibition, cardinality, and obligation constraintscan be also represented in RCL2000.