Role of Time-Domain Based Access Control Model
- 1 Department of Information Management, Hunan University of Finance and Economics, Changsha, China
- 2 Department of Information Management, Hunan University of Finance and Economics, Changsha, China
- 3 Department of Information Management, Hunan University of Finance and Economics, Changsha, China
Abstract
While Role-Based Access Control Model (RBAC) is being analyzed, the concept of Role of Time-domain Based Access Control Model (T-RBAC) is put forward. With time-domain added, both time-domain and authority control roles. The basic idea of T-RBAC is introduced and described formally, and the safely of this model is analyzed. The research shows that T-RBAC fulfills both rules of information security, which are principle of least privilege and separation of duties. With practical application of T-RBCA, it can handle most of the time-related or authority-related problems. What’s more, it also increases the security level, flexibility and dynamic adaptation of the system and has lower complexity than system only handled by authority. This model also can solve conflicts caused by authority.
- Harrison, M., Ruzzo, W. and Ullman, J. (1976) Protection in Operating Systems. CACM, 19, 461-471. http://dx.doi.org/10.1145/360303.360333
- Snyder, L. (1981) Formal Models of Capability-Based Protection Systems. IEEE Trans on Computers, 30, 172-181. http://dx.doi.org/10.1109/TC.1981.1675753
- Solworth, J.A. and Sloan, R.H. (2004) A Layered Design of Discretionary Access Controls with Decidable Safety Properties. Proceedings, 2004 IEEE Symposium on Security and Privacy, 9-12 May 2004, 56-67. http://dx.doi.org/10.1109/secpri.2004.1301315
- Li, N.H. (2008) How to Make Discretionary Access Control Secure against Trojan Horses. International Parallel and Distributed Processing Symposium/International Parallel Processing Symposium—IPDPS (IPPS), 1-3.
- Ferraiolo, D. and Kuhn, D.R. (1992) Role-Based Access Control. 15th National Computer Security Conference, Baltimore, 554-563.
- Chen, F.-Z. and Hong, F. (2003) Task-Based Access Control Model. Mini-Micro System, 24, 621-624.
- Zhao X.F. and Guo, Y.B. (2007) An Access Control Model Based on Role and Task. Information Security, 3, 63-64.
- Thomas, R.K. and Sandu, R.S. (1997) Task-Based Authorization Controls (TBAC): A Family of Models for Active and Enterprise-Oriented Authorization Management. Proceedings of the 11th IFIP WG 11.3 Conference on Database Security, Lake Tahoe, August 1997, 166-181.
- Zheng, J., Zhang, Q.K., Zheng, S.W. and Tan, Y. (2011) Dynamic Role-Based Access Control Model. Journal of Software, 6, 1096-1102. http://dx.doi.org/10.4304/jsw.6.6.1096-1102
- Uzun, E., Atluri, V., Vaidya, J., et al. (2014) Security Analysis for temporal Role Based Access Control. Journal of Computer Security, 22, 961-996.
- Müldner, T., Leighton, G. and Miziolek, J.K. (2009) Parameterized Role-Based Access Control. Information Security Journal, 18, 282-296.
- Nirmalrani, V. and Sakthivel, P. (2015) Framework for Providing Access to Web Data Bases Using Budget Aware Role Based Access Control. Journal of Theoretical and Applied Information Technology, 76, 296-308.
- Huang, J., Qing, S.H. and Wen, H.Z. (2003) Timed Role Based Access Control. Journal of Software, 14, 1944-1954.
- Guo, H., Li, Y.M. and Wang, L.F. (2006) Design and Research of Access Control Model Based on Role and Task. Computer Engineering, 32, 143-145.