Framework for Role-based Delegation Models
نویسندگان
چکیده
FRAMEWORK FOR ROLE-BASED DELEGATION MODELS Ezedin S. Barka, Ph.D. George Mason University, 2002 Dissertation Director: Dr. Ravi S. Sandhu The basic idea behind delegation is that some active entity in a system delegates authority to another active entity in order to carry out some functions on behalf of the former. Delegation can take many forms: human to human, human to machine, machine to machine, and perhaps even machine to human. In this dissertation, I focus on the human to human form of delegation. Specifically, I consider the ability of a user who is a member of a role to delegate his or her role to another user who belongs to some other role. For example, a professor in a university who is also a member in an advising committee role can delegate his/her membership in the advising committee role to another professor who belongs to another committee role. This delegation can take the form of being either permanent or temporary delegation. Moreover, the same professor can delegate only part of his/her professor role (i.e. instructor) to his/her assistant. This delegation can be only temporary. In this dissertation, I present a comprehensive approach to role-based delegation. More specifically, I identify the characteristics related to delegation, which can be used to develop delegation models; I use a systematic approach to reduce a large number of possible cases to smaller sensible ones; and I formally define and derive some delegation models using roles based on those cases. The thesis of this research is as follows: It is possible, by adding a can-delegate relation to the RBAC model in conjunction with constraints, to produce a framework for role-based delegation models. The research approach used to produce a framework for role-based delegation models is an exploratory approach. In this dissertation, the scope of my work is to address user-to-user delegation based on RBAC96. I use the RBAC96 family of models as the base for my research. I first consider temporary delegation within the framework of RBAC96-Flat-Roles (or RBAC0). Then I evolve the model to address other variations of delegation that include delegation based on role hierarchies, permanent delegation, partial delegation, delegation based on the administrator of the actual delegation, and so forth. I also address some issues that deal with revocation. In particular, I consider cascading revocation and grantindependent revocation. I chose this approach in order to work out a simple but useful model in complete detail and then to extend this model gradually to introduce other aspects to add functionality in an incremental manner. This dissertation shows that by adding a can-delegate relation to the RBAC model in conjunction with constraints, it is possible to produce a framework for role-based delegation models.
منابع مشابه
A Delegation Framework for Task-Role Based Access Control in WFMS
Access control is important for protecting information integrity in workflow management system (WfMS). Compared to conventional access control technology such as discretionary, mandatory, and role-based access control models, task-role-based access control (TRBAC) model, an access control model based on both tasks and roles, meets more requirements for modern enterprise environments. However, f...
متن کاملPrivacy Preserving Dynamic Access Control Model with Access Delegation for eHealth
eHealth is the concept of using the stored digital data to achieve clinical, educational, and administrative goals and meet the needs of patients, experts, and medical care providers. Expansion of the utilization of information technology and in particular, the Internet of Things (IoT) in eHealth, raises various challenges, where the most important one is security and access control. In this re...
متن کاملRB-GDM: A Role-Based Grid Delegation Model
Grid delegation is the procedure by which a valid user endows another user or a program or service with the ability to act on that user’s behalf. Delegation is the primary form of authorization in grids. The large and geographically distributed, dynamic, heterogeneous and scalable grid environment poses unique delegation requirements. Presently there are no standard mechanisms to guide grid del...
متن کاملRole Delegation for a Distributed, Unified RBAC/MAC*
The day-today operations of corporations and government agencies rely on inter-operating legacy, COTs, databases, clients, servers, etc., which are brought together into a distributed environment running middleware (e.g., CORBA, JINI, DCOM, etc.). Both access control and security assurance within these distributed applications is paramount. Of particular concern is the delegation of authority, ...
متن کاملOntology-Based Delegation of Access Control: An Enhancement to the XACML Delegation Profile
Delegation of access control (i.e. transferring access rights on a resource to another tenant) is crucial to efficiently decentralize the access control management in large and dynamic scenarios. Most of the delegation methods available in the literature are based on the RBAC or ABAC models. However, their applicability can be hampered by: i) the effort required to manage and enforce multiple r...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2000