A Distributed Calculus for Rôle-Based Access Control

  • Authors:
  • Chiara Braghin;Daniele Gorla;Vladimiro Sassone

  • Affiliations:
  • Univ. Ca' Foscari di Venezia;Univ. di Firenze, Univ. di Roma 'La Sapienza';University of Sussex

  • Venue:
  • CSFW '04 Proceedings of the 17th IEEE workshop on Computer Security Foundations
  • Year:
  • 2004

Quantified Score

Hi-index 0.01

Visualization

Abstract

Rôle-based access control (RBAC) is increasingly attractingattention because it reduces the complexity andcost of security administration by interposing the notion ofrôle in the assignment of permissions to users. In this paper,we present a formal framework relying on an extension ofthe 驴 calculus to study the behavior of concurrent systemsin a RBAC scenario. We define a type system ensuring thatthe specified policy is respected during computations, and abisimulation to equate systems. The theory is then appliedto three meaningful examples, namely finding the 'minimal'policy to run a given system, refining a system to be rununder a given policy (whenever possible), and minimizingthe number of users in a given system without changing theoverall behavior.