期刊论文详细信息
Symmetry
Permission-Based Separation of Duty in Dynamic Role-Based Access Control Model
NgoTung Son1  TranVan Dinh2  Oluwasanmi Ariyo3  Zakria3  MuhammadUmar Aftab3  NegalignWake Hundera3  Zhiguang Qin3 
[1] Computing Fundamental Department, FPT University, Hanoi 10000, Vietnam;Department of Computer Science, University of Freiburg, 79098 Freiburg, Germany;School of Information and Software Engineering, University of Electronic Science and Technology of China, Chengdu 610054, China;
关键词: Efficient SOD;    Dynamic RBAC;    Hybrid Access Control;    Attributed RBAC;    Permission based SOD;   
DOI  :  10.3390/sym11050669
来源: DOAJ
【 摘 要 】

A major development in the field of access control is the dominant role-based access control (RBAC) scheme. The fascination of RBAC lies in its enhanced security along with the concept of roles. In addition, attribute-based access control (ABAC) is added to the access control models, which is famous for its dynamic behavior. Separation of duty (SOD) is used for enforcing least privilege concept in RBAC and ABAC. Moreover, SOD is a powerful tool that is used to protect an organization from internal security attacks and threats. Different problems have been found in the implementation of SOD at the role level. This paper discusses that the implementation of SOD on the level of roles is not a good option. Therefore, this paper proposes a hybrid access control model to implement SOD on the basis of permissions. The first part of the proposed model is based on the addition of attributes with dynamic characteristics in the RBAC model, whereas the second part of the model implements the permission-based SOD in dynamic RBAC model. Moreover, in comparison with previous models, performance and feature analysis are performed to show the strength of dynamic RBAC model. This model improves the performance of the RBAC model in terms of time, dynamicity, and automatic permissions and roles assignment. At the same time, this model also reduces the administrator’s load and provides a flexible, dynamic, and secure access control model.

【 授权许可】

Unknown   

  文献评价指标  
  下载次数:0次 浏览次数:0次