Rule support for role-based access control

  • Authors:
  • Axel Kern;Claudia Walhorn

  • Affiliations:
  • Beta Systems Software AG, Köln, Germany;Beta Systems Software AG, Köln, Germany

  • Venue:
  • Proceedings of the tenth ACM symposium on Access control models and technologies
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

The administration of users and access rights in large enterprises is a complex and challenging task. Role-based access control (RBAC) is a powerful concept for simplifying access control. In particular, Enterprise Roles spanning across different IT systems are increasingly used as a basis for company-wide security management. However, the administration of roles in large organisations can become quite cumbersome and needs to be automated.During the past years, rules have been used to support automation of user and access rights administration. We discuss different rule-based approaches and propose a new method called rule-based provisioning of roles which combines the advantages of rules and roles.Experiences made during implementation of this approach are presented in two case studies. The results are evaluated and show that role-based access control in combination with rule-based provisioning can be successfully used in practice. A high level of automation can be achieved.