loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
18th Annual Computer Security Applications Conference (ACSAC '02)
A Model for Attribute-Based User-Role Assignment
San Diego California
December 09-December 13
ISBN: 0-7695-1828-1
Mohammad A. Al-Kahtani, George Mason University
Ravi Sandhu, SingleSignOn.net, Inc. and George Mason University
The Role-Based Access Control (RBAC) model is traditionally used to manually assign users to appropriate roles, based on a specific enterprise policy, thereby authorizing them to use the roles' permissions. In environments where the service-providing enterprise has a huge customer base this task becomes formidable. An appealing solution is to automatically assign users to roles. The central contribution of this paper is to describe a model to dynamically assign users to roles based on a finite set of rules defined by the enterprise. These rules take into consideration the attributes of users and any constraints set forth by the enterprise?s security policy. The model also allows dynamic revocation of assigned roles based on conditions specified in the security policy. The model provides a language to express these rules and defines a mechanism to determine seniority among different rules. The paper also shows how to use the model to express Mandatory Access Controls (MAC).
Citation:
Mohammad A. Al-Kahtani, Ravi Sandhu, "A Model for Attribute-Based User-Role Assignment," acsac, pp.353, 18th Annual Computer Security Applications Conference (ACSAC '02), 2002
Usage of this product signifies your acceptance of the Terms of Use.