An effective role administration model using organization structure

  • Authors:
  • Sejong Oh;Ravi Sandhu;Xinwen Zhang

  • Affiliations:
  • Dankook University, Chungnam, South Korea;George Mason University, Fairfax, VA;George Mason University, Fairfax, VA

  • Venue:
  • ACM Transactions on Information and System Security (TISSEC)
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Role-based access control (RBAC) is a well-accepted model for access control in an enterprise environment. When we apply RBAC model to large enterprises, effective role administration is a major issue. ARBAC97 is a well-known solution for decentralized RBAC administration. ARBAC97 authorizes administrative roles by means of role ranges and prerequisite conditions, where prerequisite conditions effectively work as a restricted pool for administrative roles to pick users or permissions. Although attractive and elegant in their own right, these mechanisms have significant shortcomings. In this paper, we propose an improved role administration model named ARBAC02 to overcome the weaknesses of ARBAC97. ARBAC02 introduces the concept of organization structure for defining user and permission pools independent of roles and role hierarchies, with a refined prerequisite condition specification. In addition, we present a bottom-up approach of permission-role administration in contrast to the top-down approach in ARBAC97. As a general solution, we illustrate the applications of organization structured-based security administration with other access control models, such as access control list model and lattice-based access control model.