Application Design and Execution Framework in Role-Based Access Control Systems

역할기반 접근통제 시스템에서 응용 프로그램의 설계 및 시행지원 프레임워크

  • Lee, Hyeong-Hyo (Dept.of Computer Science, Graduate School of Chonnam National Universityisy) ;
  • Choe, Eun-Bok (Dept.of Computer Science, Graduate School of Chonnam National Universityisy) ;
  • No, Bong-Nam (Dept.of Computer Science, Chonnam National University)
  • 이형효 (전남대학교 대학원 전산학과) ;
  • 최은복 (전남대학교 대학원 전산학과) ;
  • 노봉남 (전남대학교 전산학과)
  • Published : 1999.11.01

Abstract

Role-Based Access Control(RBAC) security policy is being widely accepted not only as an access control policy for information security but as both a natural modeling tool for management structure of organizations and flexible permission management framework in various commercial environments. Important functions provided by the current RBAC model are to administrate the information on the components of RBAC model and determine whether user's access request to information is granted or not, and most researches on RBAC are for defining the model itself, describing it in formal method and other important properties such as separation of duty. As the current RBAC model which does not define the definition, design and operation for applications is not suitable for automated information systems that consist of various applications, it is needed that how applications should be designed and then executed based on RBAC security model. In this paper, we describe dynamic properties of session which is taken for a passive entity only activated by users, as a vehicle for building and executing applications in an automated information systems. And, a framework for session-oriented separation of duty property, application design and operation is also presented.

Keywords