|
| This Article | ||
| ||
| Share | ||
| Bibliographic References | ||
| Add to: | ||
| | ||
| Search | ||
| ||
2009 Annual Computer Security Applications Conference
How to Securely Break into RBAC: The BTG-RBAC Model
Honolulu, Hawaii
December 07-December 11
ISBN: 978-0-7695-3919-5
| ASCII Text | x | ||
| Ana Ferreira, David Chadwick, Pedro Farinha, Ricardo Correia, Gansen Zao, Rui Chilro, Luis Antunes, "How to Securely Break into RBAC: The BTG-RBAC Model," Computer Security Applications Conference, Annual, pp. 23-31, 2009 Annual Computer Security Applications Conference, 2009. | |||
| BibTex | x | ||
| @article{ 10.1109/ACSAC.2009.12, author = {Ana Ferreira and David Chadwick and Pedro Farinha and Ricardo Correia and Gansen Zao and Rui Chilro and Luis Antunes}, title = {How to Securely Break into RBAC: The BTG-RBAC Model}, journal ={Computer Security Applications Conference, Annual}, volume = {0}, year = {2009}, issn = {1063-9527}, pages = {23-31}, doi = {http://doi.ieeecomputersociety.org/10.1109/ACSAC.2009.12}, publisher = {IEEE Computer Society}, address = {Los Alamitos, CA, USA}, } | |||
| RefWorks Procite/RefMan/Endnote | x | ||
| TY - CONF JO - Computer Security Applications Conference, Annual TI - How to Securely Break into RBAC: The BTG-RBAC Model SN - 1063-9527 SP23 EP31 A1 - Ana Ferreira, A1 - David Chadwick, A1 - Pedro Farinha, A1 - Ricardo Correia, A1 - Gansen Zao, A1 - Rui Chilro, A1 - Luis Antunes, PY - 2009 KW - Access control model KW - NIST Core RBAC KW - Break The Glass KW - Obligations VL - 0 JA - Computer Security Applications Conference, Annual ER - | |||
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ACSAC.2009.12
Access control models describe frameworks that dictate how subjects (e.g. users) access resources. In the Role-Based Access Control (RBAC) model access to resources is based on the role the user holds within the organization. RBAC is a rigid model where access control decisions have only two output options: Grant or Deny. Break The Glass (BTG) policies on the other hand are flexible and allow users to break or override the access controls in a controlled and justifiable manner. The main objective of this paper is to integrate BTG within the NIST/ANSI RBAC model in a transparent and secure way so that it can be adopted generically in any domain where unanticipated or emergency situations may occur. The new proposed model, called BTG-RBAC, provides a third decision option BTG, which grants authorized users permission to break the glass rather than be denied access. This can easily be implemented in any application without major changes to either the application code or the RBAC authorization infrastructure, apart from the decision engine. Finally, in order to validate the model, we discuss how the BTG-RBAC model is being introduced within a Portuguese healthcare institution where the legislation requires that genetic information must be accessed by a restricted group of healthcare professionals. These professionals, advised by the ethical committee, have required and asked for the implementation of the BTG concept in order to comply with the said legislation.
Index Terms:
Access control model, NIST Core RBAC, Break The Glass, Obligations
Citation:
Ana Ferreira, David Chadwick, Pedro Farinha, Ricardo Correia, Gansen Zao, Rui Chilro, Luis Antunes, "How to Securely Break into RBAC: The BTG-RBAC Model," acsac, pp.23-31, 2009 Annual Computer Security Applications Conference, 2009
Usage of this product signifies your acceptance of the Terms of Use.
