CERIAS Security: Administrative Scope and Role-Based Administration 6/6

Опубликовано: 24 Октябрь 2024
на канале: Christiaan008
73
0

Clip 6/6
Speaker: Jason Crampton · Royal Holloway, University of London

Role-based access control (RBAC) has received considerable attention in recent years, resulting in several important theoretical models and increasing use in commercial products. Nevertheless, role-based administration, the use of role-based techniques to control RBAC systems, has been less widely studied.

We will consider the problem of controlling the propagation of authorization information in computer systems in general, and in role-based systems in particular. We will then introduce the concept of administrative scope, an intuitive notion corresponding to the set of role(s) that can be controlled by a given role, and demonstrate how this can be used as the fundamental unit in the development of a family of administrative models for RBAC systems. We compare the characteristics of these models with the well-known ARBAC97 administrative model. We conclude by discussing how administrative scope can be used to provide an administrative framework for more complex RBAC models.

For more information go to the Cerias website (http://bit.ly/dsFCBF)