Obligations for Role Based Access Control

  • Authors:
  • Gansen Zhao;David Chadwick;Sassa Otenko

  • Affiliations:
  • University of Kent, UK;University of Kent, UK;University of Kent, UK

  • Venue:
  • AINAW '07 Proceedings of the 21st International Conference on Advanced Information Networking and Applications Workshops - Volume 01
  • Year:
  • 2007

Quantified Score

Hi-index 0.02

Visualization

Abstract

Role based access control has been widely researched in security critical systems. Conventional role based access control is a passive model, which makes authorization decisions on requests, and the authorization decisions contain only information about whether the corresponding requests are authorised or denied. One of the potential improvements for role based access control is the augmentation of obligations, where obligations are tasks and requirements to be fulfilled before, after or together with the enforcement of the authorization decisions. This paper conducts a literature review of role based access control and obligation related research, and proposes a design for the augmentation of obligations in the context of the RBAC standard. The design is then validated by implementation in the PERMIS RBAC authorization infrastructure. The paper also discusses the possible nondeterminism caused by overlapping authorisations.