Abstract

While Role-Based Access Control Model (RBAC) is being analyzed, the concept of Role of Time-domain Based Access Control Model (T-RBAC) is put forward. With time-domain added, both time-domain and authority control roles. The basic idea of T-RBAC is introduced and described formally, and the safely of this model is analyzed. The research shows that T-RBAC fulfills both rules of information security, which are principle of least privilege and separation of duties. With practical application of T-RBCA, it can handle most of the time-related or authority-related problems. What’s more, it also increases the security level, flexibility and dynamic adaptation of the system and has lower complexity than system only handled by authority. This model also can solve conflicts caused by authority.

Highlights

  • With the continuous development of computer network and distributed technology, enterprises are increasingly focused on information management and data sharing, leading to data security challenges

  • In recent years hotspot of access control technology research focused on role-based access control (RBAC) which is proposed by Ferraiolo and Kuhn [5] and task-based access controls (TBAC) which is proposed by Kuhn [6]-[8], but there are some other related research, such as dynamic role-based access control model [9], a suitable administrative model that governs changes to temporal policies [10], parameterized role-based access control [11], a framework using Budget-Aware Role Based Access Control (BARBAC) [12], adding time features [13] [14] or joining the task access control [15] [16] and so on

  • In order to solve this problem, the time-domain is introduced on the basis of RBAC model, this makes the permissions of the roles have time limitation, the role of operating authority will be effective on the corresponding time-domain

Read more

Summary

Introduction

With the continuous development of computer network and distributed technology, enterprises are increasingly focused on information management and data sharing, leading to data security challenges. The paper puts forward a kind of RBAC model based on time domain (T-RBAC). User role permissions are controlled by time domain. The user can get permanent authority and be able to get a certain period of time to get some permissions. This is a task instance to reach the limits of time domain control. Control time domain activates these specify access permission. The role of activated permissions operation data and tasks of life cycle is the time domain. When the task is complete, the activation of temporal authority fails. (2016) Role of Time-Domain Based Access Control Model.

Background and Related Work
Role of Time-Domain Based Access Control
Formal Definition of T-RBAC
The Working Mechanisms of T-RBAC
Safety Performance Analysis of T-RBAC
Conclusions and Application
Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call