Reference : A Comprehensive Modeling Framework for Role-based Access Control Policies
Scientific journals : Article
Engineering, computing & technology : Computer science
Engineering, computing & technology : Computer science
http://hdl.handle.net/10993/21025
A Comprehensive Modeling Framework for Role-based Access Control Policies
English
Ben Fadhel, Ameni mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > >]
Bianculli, Domenico mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > >]
Briand, Lionel mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > > ; University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)]
29-May-2015
Journal of Systems and Software
Elsevier Science
107
September,2015
110-126
Yes (verified by ORBilu)
International
0164-1212
[en] role-based access control ; modeling, authorization constraints ; survey
[en] Prohibiting unauthorized access to critical resources and data has become a major requirement for enter- prises; access control (AC) mechanisms manage requests from users to access system resources. One of the most used AC paradigms is role-based access control (RBAC), in which access rights are determined based on the user’s role.
Many different types of RBAC policies have been proposed in the literature, each one accompanied by the corresponding extension of the original RBAC model. However, there is no unified framework that can be used to define all these types of policies in a coherent way, using a common model.
In this paper we propose a model-driven engineering approach, based on UML and the Object Constraint Language (OCL), to enable the precise specification and verification of such policies. More specifically, we first present a taxonomy of the various types of RBAC policies proposed in the literature. We also propose the GemRBAC model, a generalized model for RBAC that includes all the entities required to define the classified policies. This model is a conceptual model that can also serve as data model to operationalize data collection and verification. Lastly, we formalize the classified policies as OCL constraints on the GemRBAC model.
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Software Verification and Validation Lab (SVV Lab)
Fonds National de la Recherche - FnR
http://hdl.handle.net/10993/21025
10.1016/j.jss.2015.05.015
http://www.sciencedirect.com/science/article/pii/S0164121215001041

File(s) associated to this reference

Fulltext file(s):

FileCommentaryVersionSizeAccess
Limited access
JSS-GemRBAC2015.pdfAuthor postprint597.44 kBRequest a copy

Bookmark and Share SFX Query

All documents in ORBilu are protected by a user license.