2021
DOI: 10.1007/s10796-021-10167-z
|View full text |Cite
|
Sign up to set email alerts
|

A Role-Based Administrative Model for Administration of Heterogeneous Access Control Policies and its Security Analysis

Abstract: Over the past few years, several efforts have been made to enable specification and enforcement of flexible and dynamic access control policies using traditional access control (such as role based access control (RBAC), etc.) and attribute based access control (ABAC). Recently, a unified framework, named MPBAC (meta-policy based access control), has been developed to enable specification and enforcement of heterogeneous access control policies such as ABAC, RBAC and a combination of policies (such as ABAC and … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
6
0

Year Published

2022
2022
2023
2023

Publication Types

Select...
3
2
1

Relationship

0
6

Authors

Journals

citations
Cited by 7 publications
(6 citation statements)
references
References 52 publications
0
6
0
Order By: Relevance
“…• Effective administration is vital for managing access authorization changes, policy configurations, and access control-related attributes (creation, adjustment and updates) [88], [89]. Administering access control systems is necessary to accommodate changes and ensure their continued operation.…”
Section: Discussionmentioning
confidence: 99%
“…• Effective administration is vital for managing access authorization changes, policy configurations, and access control-related attributes (creation, adjustment and updates) [88], [89]. Administering access control systems is necessary to accommodate changes and ensure their continued operation.…”
Section: Discussionmentioning
confidence: 99%
“…To address this, Singh et al [16] have presented a framework that enables the specification and enforcement of heterogeneous access control policies, such as RBAC and ABAC, as data in the Database. Additionally, Singh et al [17] have also presented a novel methodology for analyzing the security properties of heterogeneous access control policies. The proposed methodology models policies as facts using Datalog and analyses them through the μz tool in the presence of the administrative model.…”
Section: Security Analysis Of Rbacmentioning
confidence: 99%
“…This model is suitable for environments with a clear organizational structure and few role changes.Kamboj et al [2] proposed a RBAC model based on blockchain smart contracts to deal with attack methods such as man-in-the-middle attacks in organizational scenarios. The approach uses the ethereum blockchain platform and its smart contract functionality to model user resource communication.Singh et al in [3] proposed a complete role-based management model (named RAMHAC) to manage heterogeneous access control policies. We also introduce a new approach to analyze the presence of heterogeneous access control policies in RAMHAC by modeling the policies with Datalog facts and using the μz tool.…”
Section: Access Control Policies and Modelsmentioning
confidence: 99%