• Title/Summary/Keyword: 역할계층

Search Result 536, Processing Time 0.025 seconds

Role Based Access Control Model contains Role Hierarchy (역할계층을 포함하는 역할기반 접근통제 모델)

  • 김학범;김석우
    • Convergence Security Journal
    • /
    • v.2 no.2
    • /
    • pp.49-58
    • /
    • 2002
  • RBAC(Role Based Access Control) is an access control method based on the application concept of role instead of DAC(Discretionary Access Control) or MAC(Mandatory Access Control) based on the abstract basic concept. Model provides more flexibility and applicability on the various computer and network security fields than the limited 1functionality of kernel access control orginated from BLP model. In this paper, we propose $ERBAC_0$ (Extended $RBAC_0$ ) model by considering subject's and object's roles and the role hierarchy result from the roles additionally to $RBAC_0$ base model. The proposed $ERBAC_0$ model assigns hierarchically finer role on the base of subject and object level and provides flexible access control services than traditional $RBAC_0$ model.

  • PDF

The Impact of Children's Education Level on Intergenerational Income Persistence (자녀의 학력이 부자간 소득계층 대물림에 미치는 영향)

  • Lee, Jin Young
    • Journal of Labour Economics
    • /
    • v.40 no.3
    • /
    • pp.1-28
    • /
    • 2017
  • Using Korea Labor and Income Panel Surveys data, this paper estimates the effect of schooling level on income over time and the effect of children's education level on intergenerational income persistence. The results show that the impact of education level on income decreased over time. Also, intergenerational income persistence, measured as a dummy variable that has value one if children's income percentile group is same as the father's, increased with children's educational attainment only when the father is in upper income percentile groups. These findings indicate that education fails to play a significant role of the economic ladder and does not much help in raising intergenerational income mobility. Rather, education may possibly function as a means of intergenerational transmission of wealth through parental investment in their children's private education.

  • PDF

Access Control of XML Object Using Role Hierarchy and Cryptographic Key Assignment Scheme (역할 계층과 암호학적인 키 할당 기법을 이용한 XML 객체의 접근제어)

  • Bae Kyoung-Man;Kim Jong-Hoon;Ban Yong-Ho
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.15 no.6
    • /
    • pp.93-103
    • /
    • 2005
  • As the usage of XML documents increases the requirement of security for XML documents is growing. Especially it is very important to solve the problem of access control to XML object which shares in the environment where various users connect to each others. In this paper, we propose the access control model and mechanism which is combined with role hierarchy in the RBAC and hierarchical key derivation/assign method for the access to XML object. So we implement the access control mechanism by including hierarchical key derivation method. The technique, we proposed, gives not only the benefit in management which RBAC provides in access control to XML objects, but also it ran help derive a lower layer key from the higher layer user's. This feature decrease the number of keys managed in each role hierarchy in comparison with previous methods.

Multi-Step Delegation Based On Task-Role-Based Access Control Model (T-RBAC에 기반한 사용자 수준의 다단계 위임기법)

  • Na, Min-Sun;Park, Seog
    • Proceedings of the Korean Information Science Society Conference
    • /
    • 2002.04a
    • /
    • pp.871-873
    • /
    • 2002
  • RBAC은 역할 계층구조에서 권한의 계승과 의무분리와 같은 제약조건을 다룸으로써 접근권한의 관리를 수월하게 하고 기업환경을 잘 반영말 수 있는 장점이 있다. 하지만 RBAC은 현실세계의 기업환경에서 빈번히 이루어지는 권한의 위임을 제대로 구현하지 못한다는 문제점을 가지고 있다. 본 논문에서는 자신의 고유역할 뿐만 아니라 상위 역할로부터 위임받은 새로운 위임 역할을 생성함으로써 역할계층 구조상의 다른 역할의 사용자에게 다른 과업을 할당해 줄 수 있도록 하여, 최소 권한의 원칙을 만족하는 다단계 위임을 구현하였다. 위임 시에 생길 수 있는 보안 문제를 해결하기 위해서 역할단위가 아닌 과업단위의 위임으로 제안하고, 과업단위의 의무분리를 적용하였으며, 위임 할 수 있는 과업을 규정하고 최하위 역할을 지정하였다. 기존의 다단계 모델에서 제안된 기법과의 비교를 통해서 본 논문에서 제안된 기법이 실제 기업에서 이루어지는 다단계 위임을 타당하게 구현할 수 있음을 보인다. 또한 T-RBCA을 기반으로 ARBAC97을 적용해서 제안된 기법을 모델링하고 Prototype을 구현하였다.

  • PDF

A Role-Based Delegation Model Using Role Hierarchy with Restricted Permission Inheritance (권한상속제한 역할계층을 이용한 역할기반 위임 모델)

  • 박종순;이영록;이형효;노봉남;조상래
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.13 no.4
    • /
    • pp.129-138
    • /
    • 2003
  • Role-Based Access Control(RBAC) model is becoming a promising model for enterprise environments with various organization structures. In terms of role hierarchy, each senior role inherits all the permissions of its junior roles in the role hierarchy, and a user who is a member of senior role is authorized to carry out the inherited permissions as well as his/her own ones. But there is a possibility for senior role members to abuse permissions. Since senior role members need not have all the authority of junior roles in the real world, enterprise environments require a restricted inheritance rather than a unconditional or blocked inheritance. In this paper, we propose a new role-based delegation model using the role hierarchy model with restricted inheritance functionality, in which security administrator can easily control permission inheritance behavior using sub-roles. Also, we describe how role-based user-to-user, role-to-role delegations are accomplished in the model and the characteristics of the proposed role-based delegation model.

CORBA based Hierarchical Control and Monitoring Architecture for Unmanned Autonomous Helicopters (자율 비행 무인 헬리콥터를 위한 코바 기반의 계층화된 제어 및 모니터링 구조)

  • 노인호;오주용;강순주
    • Proceedings of the Korean Information Science Society Conference
    • /
    • 2003.04c
    • /
    • pp.103-105
    • /
    • 2003
  • 본 논문에서는 자율 비행 무인 헬리콥터를 위한 코바 기반의 계층화 구조를 제안한다. 제안된 소프트웨어 구조에서는 데이터의 추상화 및 기능에 따라 하드웨어 계층, 실행 계층, 논리적 추상화 계층 및 서비스 에이전트 계층으로 구성하고 각 계층의 역할을 정의한다. 또한, 코바를 이용하여 상위의 추상화된 계층을 객체화시킴으로써, 소프트웨어의 재사용성과 유연성을 높일 수 있는 구조에 대해서 서술한다.

  • PDF

An Integrated Management Model of OS-RBAC and Separation Of Duty Policy (OS-RBAC과 임무분리 정책의 통합 관리 모델)

  • Byun, Chang-Woo
    • Journal of the Korea Society of Computer and Information
    • /
    • v.15 no.1
    • /
    • pp.167-175
    • /
    • 2010
  • Like most large organizations, there are business rules such as 'separation of duty' and 'delegation' which should be considered in access control. From a SOD point of view, previous SOD models built on the (Administrative) Role-Based Access Control model cannot present the best solution to security problems such as information integrity by the limited constituent units such as role hierarchy and role inheritance. Thus, we propose a new integrated management model of administration role-based access control model and SOD policy, which is called the OS-SoDAM. The OS-SoDAM defines the authority range in an organizational structure that is separated from role hierarchy and supports a decentralized security officer-level SOD policy in which a local security officer can freely perform SOD policies within a security officer's authority range without the security officer's intervention.

Analysis on the Movement of the Creative Class (창조계층의 이동에 관한 연구)

  • Joo, Mijin
    • The Journal of the Korea Contents Association
    • /
    • v.17 no.5
    • /
    • pp.376-387
    • /
    • 2017
  • The creative class is the class of workers whose job is to create meaningful new forms. Recently, much attention has been focused on the role of the creative class in regional development. Many policy makers have invested to amenities to attract more creative class into their cities or regions for regional economic growth. However, there are only a few studies about the migration of the creative class in Korea. The purpose of this study is to make an analysis of the movement of the creative class by using the 17th Korean Labor & Income Panel Study. According to empirical results, the creative class are more likely to move than the non-creative class. The characteristic of creative class who moved is related to married man aged 20s and 30s without own house. Also, there is the difference between determinants of migration of the creative class and the non-creative class. It was founded that the most important determinants of migration of the creative class are housing related reasons such as home ownership and job reasons. Relationship, convenient facilities are not important factors when the creative class make a decision to move.

An Implementation of Hierarchical RBAC(Role Based Access Control) API using Database (데이터베이스를 이용한 RBAC(역할기반 접근제어) 서버 API 구현)

  • Kim Jin Sik;Kim Min Young;Lee Sang-Won
    • Proceedings of the Korean Information Science Society Conference
    • /
    • 2005.11b
    • /
    • pp.199-201
    • /
    • 2005
  • RBAC(Role Based Access Control) 이란 특정 사용자가 어떤 대상에 특정 행동을 하는 데에 있어서 그 사용자가 가진 역할 (Role) 에 의해 접근 가능유무를 판정하게 하는 방법이다. 그 RBAC 에 역할간의 계층관계를 추가한 것이 계층적 RBAC (Hierarchicai RBAC)이다. 본 논문에서는 그런 다른 어플리케이션에 쉽게 추가 되거나 아니면 독자적으로 인증 기능을 가지는 계층적 RBAC 서버에 사용될 수 있는 API 와 그와 관련된 응용 어플리케이션을 자바와 데이터베이스를 이용하여 설계 및 구현하였다.

  • PDF

고자치 시스템 설계를 위한 모델베이스 개념

  • 지승도
    • 전기의세계
    • /
    • v.42 no.3
    • /
    • pp.3-11
    • /
    • 1993
  • 본 논문에서는 공장자동화, 우주로보트, 심해 자동차 등 여러 응용분야에서 새롭게 대두되는 고자치 시스템의 접근방법들과 시스템적인 개념들을 소개하였다. 이 분야에서의 주된 관심사는 상위계층의 기호적 모델과 하위계층의 도역학적(제어이론적) 모델간의 체계적 통합에 있다고 볼 수 있다. 즉, 프랜닝, 작동, 고장진단 및 수리 등과 같은 지능적 기능들을 제공할 수 있는 여러 계층의 동역학적 및 기호적 모델들의 유기적인 포괄 및 추상화에 의해서만 현존하는 다계층 제어 및 정보구조를 확장해 나갈 수 있을 것이다. 그러므로 고자치 시스템의 디자인을 위해서는 여러 분야의 팀단위의 노력이 경주되어야만 할 것이다. 디자인상의 난제로는 인간과 로보트간의 기능적 분할 그리고 상위화 하위간의 자동화를 위한 역할 분담등을 들 수 있다.

  • PDF