XacT: a bridge between resource management and access control in multi-layered applications

  • Authors:
  • Maarten Rits;Benjamin De Boe;Andreas Schaad

  • Affiliations:
  • SAP Research, Font de l'Orme, Mougins;SAP Research, Font de l'Orme, Mougins;SAP Research, Font de l'Orme, Mougins

  • Venue:
  • SESS '05 Proceedings of the 2005 workshop on Software engineering for secure systems—building trustworthy applications
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we describe the eXtreme access control Tool (XacT) which provides an automated way to obtain access control information out of multi-layered applications. We believe that based on this information consistent access control policies can be specified to prevent over-privileged accounts. The main difficulty, that leads to these over-privileged accounts, comes from the distinction that must be made between identifying which users should perform a workflow task (resource management) and which users are allowed to perform a task (access control), as well as the fact that access control enforcement is typically spread over different layers in applications (e.g. database layer, operating system layer, workflow layer). In this paper, we present an automated way to obtain access control information out of multi-layered applications. We base our observations on recent insights into workflow controlled judicial information systems.