Article (Périodiques scientifiques)
A Comprehensive Modeling Framework for Role-based Access Control Policies
BEN FADHEL, Ameni; BIANCULLI, Domenico; BRIAND, Lionel
2015In Journal of Systems and Software, 107 (September,2015), p. 110-126
Peer reviewed vérifié par ORBi
 

Documents


Texte intégral
JSS-GemRBAC2015.pdf
Postprint Auteur (611.77 kB)
Demander un accès

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
role-based access control; modeling, authorization constraints; survey
Résumé :
[en] Prohibiting unauthorized access to critical resources and data has become a major requirement for enter- prises; access control (AC) mechanisms manage requests from users to access system resources. One of the most used AC paradigms is role-based access control (RBAC), in which access rights are determined based on the user’s role. Many different types of RBAC policies have been proposed in the literature, each one accompanied by the corresponding extension of the original RBAC model. However, there is no unified framework that can be used to define all these types of policies in a coherent way, using a common model. In this paper we propose a model-driven engineering approach, based on UML and the Object Constraint Language (OCL), to enable the precise specification and verification of such policies. More specifically, we first present a taxonomy of the various types of RBAC policies proposed in the literature. We also propose the GemRBAC model, a generalized model for RBAC that includes all the entities required to define the classified policies. This model is a conceptual model that can also serve as data model to operationalize data collection and verification. Lastly, we formalize the classified policies as OCL constraints on the GemRBAC model.
Centre de recherche :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Software Verification and Validation Lab (SVV Lab)
Disciplines :
Sciences informatiques
Sciences informatiques
Auteur, co-auteur :
BEN FADHEL, Ameni ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
BIANCULLI, Domenico  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
BRIAND, Lionel ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) ; University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Co-auteurs externes :
no
Langue du document :
Anglais
Titre :
A Comprehensive Modeling Framework for Role-based Access Control Policies
Date de publication/diffusion :
29 mai 2015
Titre du périodique :
Journal of Systems and Software
ISSN :
0164-1212
eISSN :
1873-1228
Maison d'édition :
Elsevier Science
Volume/Tome :
107
Fascicule/Saison :
September,2015
Pagination :
110-126
Peer reviewed :
Peer reviewed vérifié par ORBi
Organisme subsidiant :
FNR - Fonds National de la Recherche
Disponible sur ORBilu :
depuis le 13 mai 2015

Statistiques


Nombre de vues
502 (dont 58 Unilu)
Nombre de téléchargements
3 (dont 3 Unilu)

citations Scopus®
 
31
citations Scopus®
sans auto-citations
27
OpenCitations
 
18
citations OpenAlex
 
32
citations WoS
 
18

Bibliographie


Publications similaires



Contacter ORBilu