22nd International Conference on Advanced Information Networking and Applications (aina 2008)
Synchronization of Transactions to Prevent Illegal Information Flow in a Role-Based Access Control Model
March 25-March 28
ISBN: 978-0-7695-3095-6
The role-based access control (RBAC) model is widely used to make information systems secure. Even if every access request is authorized in the roles, illegal information flow might occur as the well known confinement problem. In this paper, we discuss how to prevent illegal information flow to occur by synchronizing conflicting transactions in the RBAC model. We define types of information flow relations, legal (LIF), illegal (IIF), and possibly illegal (PIF) ones among a pair of role families.
Index Terms:
Information Flow, Rrole-based access control, Confinement problem
Citation:
Tomoya Enokido, Makoto Takizawa, "Synchronization of Transactions to Prevent Illegal Information Flow in a Role-Based Access Control Model," aina, pp.779-786, 22nd International Conference on Advanced Information Networking and Applications (aina 2008), 2008