Towards Dynamically Administered Role-Based Access Control

  • Authors:
  • Andreas K. Mattas;Ioannis K. Mavridis;George I. Pangalos

  • Affiliations:
  • -;-;-

  • Venue:
  • DEXA '03 Proceedings of the 14th International Workshop on Database and Expert Systems Applications
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

In digital business, the need for efficient frameworks toaddress the multifaceted security issues related to Web-basedapplications, has led to efforts towards thedevelopment of dynamically administered access controlsystems that implement robust access control models, toallow controlled access of information based on contentor context of processing, and secure interoperation in adynamic distributed enterprise environment. Pure RBACseems to be suitable for function-oriented organizationstructures usually used in relatively stable environments.On the other hand, TBAC and TMAC provide acomplementary support in environments that are basedon process-oriented organization structures. However,current organizational alternatives lead to thecombination of the above approaches, in the form of amatrix organization structure that maximizes theadvantages of functional and process-oriented structuresand introduces the need for new access controladministration paradigms. In this paper we discuss ourapproach for dynamically administered role-based accesscontrol, which covers the need-to-know requirements ofusers and missions are involved with, and provides tightand just-in-time access control without sacrificingoperability and simplicity of administration.