• Title/Summary/Keyword: Flexible Permission Management

Search Result 8, Processing Time 0.019 seconds

Design and Implementation of a Flexible Application Permission Management Scheme on Android Platform (안드로이드 플랫폼에서 유연한 응용프로그램 권한관리 기법 설계 및 구현)

  • Kim, Ik-Hwan;Kim, Tae-Hyoun
    • The KIPS Transactions:PartC
    • /
    • v.18C no.3
    • /
    • pp.151-156
    • /
    • 2011
  • Google Android, which is one of the popular smart phone platforms, employs a security model based on application permissions. This model intends to reduce security threats by protecting inappropriate accesses to system resources from applications, but this model has a few problems. First, permission requested by an application cannot be granted selectively. Second, once the permission has been granted it is maintained until the application is uninstalled. Third, applications may acquire powerful permissions through user ID sharing without any notice to users. In order to overcome these limitations, we designed and implemented a flexible application permission management scheme. The goal of our scheme is to enhance security and user convenience while keeping compatibility to original platform. We also verified the operation of our scheme with real applications on Android emulator.

APDM : Adding Attributes to Permission-Based Delegation Model

  • Kim, Si-Myeong;Han, Sang-Hoon
    • Journal of the Korea Society of Computer and Information
    • /
    • v.27 no.2
    • /
    • pp.107-114
    • /
    • 2022
  • Delegation is a powerful mechanism that allocates access rights to users to provide flexible and dynamic access control decisions. It is also particularly useful in a distributed environment. Among the representative delegation models, the RBDM0 and RDM2000 models are role delegation as the user to user delegation. However, In RBAC, the concept of inheritance of the role class is not well harmonized with the management rules of the actual corporate organization. In this paper, we propose an Adding Attributes on Permission-Based Delegation Model (ABDM) that guarantees the permanence of delegated permissions. It does not violate the separation of duty and security principle of least privilege. ABDM based on RBAC model, supports both the role to role and user to user delegation with an attribute. whenever the delegator wants the permission can be withdrawn, and A delegator can give permission to a delegatee.

Design of Security Management Function for SNMPv3 using Role-Based Access Control Model (역할기반 접근통제 모델을 이용한 SNMPv3 보안관리기능 설계)

  • 이형효
    • Proceedings of the Korea Society for Industrial Systems Conference
    • /
    • 2001.05a
    • /
    • pp.1-10
    • /
    • 2001
  • SNMPv3 provides the security services such as authentication and privacy of messages as well as a new flexible and extensible administration framework. Therefore, with the security services enabled by SNMPv3, network managers can monitor and control the operation of network components more secure way than before. But, due to the user-centric security management and the deficiency of policy-based security management facility, SNMPv3 might be inadequate network management solution for large-scaled networks. In this paper, we review the problems of the SNMPv3 security services, and propose a Role-based Security Management Model(RSM), which greatly reduces the complexity of permission management by specifying and enforcing a security management policy far entire network.

  • PDF

Application Design and Execution Framework in Role-Based Access Control Systems (역할기반 접근통제 시스템에서 응용 프로그램의 설계 및 시행지원 프레임워크)

  • Lee, Hyeong-Hyo;Choe, Eun-Bok;No, Bong-Nam
    • The Transactions of the Korea Information Processing Society
    • /
    • v.6 no.11
    • /
    • pp.3020-3033
    • /
    • 1999
  • Role-Based Access Control(RBAC) security policy is being widely accepted not only as an access control policy for information security but as both a natural modeling tool for management structure of organizations and flexible permission management framework in various commercial environments. Important functions provided by the current RBAC model are to administrate the information on the components of RBAC model and determine whether user's access request to information is granted or not, and most researches on RBAC are for defining the model itself, describing it in formal method and other important properties such as separation of duty. As the current RBAC model which does not define the definition, design and operation for applications is not suitable for automated information systems that consist of various applications, it is needed that how applications should be designed and then executed based on RBAC security model. In this paper, we describe dynamic properties of session which is taken for a passive entity only activated by users, as a vehicle for building and executing applications in an automated information systems. And, a framework for session-oriented separation of duty property, application design and operation is also presented.

  • PDF

Evaluation of flexible criteria for river flow management with consideration of spatio-temporal flow variation (시·공간적 유량 변화를 고려한 탄력적 하천관리 기준유량 산정 및 평가)

  • Park, Jung Eun;Kim, Han Na;Ryoo, Kyong Sik;Lee, Eul Rae
    • Journal of Korea Water Resources Association
    • /
    • v.49 no.8
    • /
    • pp.673-683
    • /
    • 2016
  • An Idea to estimate flexible criteria for river water use permits was proposed that takes the spatio-temporal flow variation along the river into account, which was applied to the Keumho River, one of the tributary of the Nakdong River in Korea. This idea implies the temporal division of four periods with different criteria, combining flood/non-flood seasons and irrigation/non-irrigation periods, while a single one has been applied throughout the year in the current practice. Through flow regime analysis of daily natural flow simulations at Dongchon and Seongseo, the control points of the study area, Q355 and 1Q10 for non-flood and non-irrigation period, Q275 for non-flood and irrigation period, Q185 for flood and irrigation period were suggested respectively. So, those values that subtract instream flow were determined as the flexible criteria in each season. From the comparison of current practice and the proposed method, it was estimated that $10.6\;million\;m^3/year$ is available for more water use permits without additional development of water storage. Therefore, it is conceived that flexible criteria for river water use permission suggested in this study can contribute to improve the national policies for more efficient water resources management in the future.

A Study on the Permit Method for a New or an Enlarged Facilities According to the Implementation of Air Pollutant Emission-Cap Regulation in Metropolitan Area (수도권 사업장 대기총량제 시행에 따른 신·증설 사업장 허가기준 개발 연구)

  • Kim, Hong-Rok;Yoon, Young-Bong;Ko, Byung-Churl;Shin, Won-Geun;Kim, Dong-Joong;Lee, Myung-Hwoon
    • Journal of Environmental Impact Assessment
    • /
    • v.16 no.4
    • /
    • pp.301-310
    • /
    • 2007
  • For the improvement of air quality in the metropolitan area, Korea has enforced the air pollutant emission cap regulation from the 1st of July, 2007, and the companies that intend to install a new or an enlarged facility in the metropolitan area will be restricted. However, the current regulation on permission does not describe a standard of judgement distinctly. In this study, therefore, a method of permission on the installation of a new or an enlarged facility was developed by supplementing the law in force based on the foreign cases. To develop a specific permit regulation and procedure, the developed nations' cases such as US, Canada, EU were reviewed thoroughly. Also, an appropriate method was suggested to apply domestically for a new or an enlarged facility permit within the regulations of the metropolitan special law. The method consists of first, calculating the possible permit quantity from the difference between an estimated annual emission cap and the annual emission provided by the implementation plan in each region. Second, permitting a new or an enlarged facility construction within the difference of the emission between the regional emission cap and the implementation plan in 2014. Third, distributing emissions allowable to each performance year based on the regional emission cap and the implementation plan in 2014. Fourth, making use of the emission difference between the implementation plan and the performance result in each year. Considering the general domestic conditions, the convenience of the permit authority and permitted companies, the most reasonable method was to use the fourth. To enforce the suggested permit method in a more flexible way, parts of the related regulations need to be revised and continuous research and analysis on the results from the implemented system and on foreign cases is necessary to develop this method a suitable system for domestic conditions and to settle the air pollutant emission cap system.

Diabetes Management and Hypoglycemia in Safety Sensitive Jobs

  • Lee, See-Muah;Koh, David;Chui, Winnie Kl;Sum, Chee-Fang
    • Safety and Health at Work
    • /
    • v.2 no.1
    • /
    • pp.9-16
    • /
    • 2011
  • The majority of people diagnosed with diabetes mellitus are in the working age group in developing countries. The interrelationship of diabetes and work, that is, diabetes affecting work and work affecting diabetes, becomes an important issue for these people. Therapeutic options for the diabetic worker have been developed, and currently include various insulins, insulin sensitizers and secretagogues, incretin mimetics and enhancers, and alpha glucosidase inhibitors. Hypoglycemia and hypoglycaemic unawareness are important and unwanted treatment side effects. The risk they pose with respect to cognitive impairment can have safety implications. The understanding of the therapeutic options in the management of diabetic workers, blood glucose awareness training, and self-monitoring blood glucose will help to mitigate this risk. Employment decisions must also take into account the extent to which the jobs performed by the worker are safety sensitive. A risk assessment matrix, based on the extent to which a job is considered safety sensitive and based on the severity of the hypoglycaemia, may assist in determining one's fitness to work. Support at the workplace, such as a provision of healthy food options and arrangements for affected workers will be helpful for such workers. Arrangements include permission to carry and consume emergency sugar, flexible meal times, selfmonitoring blood glucose when required, storage/disposal facilities for medicine such as insulin and needles, time off for medical appointments, and structured self-help programs.

A Formal Specification of Role Graph Model Increasing Integrity (무결성이 강화된 역할 그래프 모델의 정형적 명세)

  • Choi EunBok;Lee HyeongOk
    • Journal of Korea Multimedia Society
    • /
    • v.7 no.11
    • /
    • pp.1620-1629
    • /
    • 2004
  • The objectives of access control are to protect computing and communication resources from illegal use, alteration, disclosure and destruction by unauthorized users. Although Biba security model is well suited for protecting the integrity of information, it is considered too restrictive to be an access control model for commercial environments. And, Role-Based Access Control(RBAC) model, a flexible and policy-neutral security model that is being widely accepted in commercial areas, has a possibility for compromising integrity of information. In this paper, We present the role graph model which enhanced flexibility and integrity to management of many access permission. Also, In order to represent those rule and constraints clearly, formal descriptions of role assignment rule and constraints in Z language are also given.

  • PDF