Security analysis for temporal role based access control.

Saved in:
Bibliographic Details
Title: Security analysis for temporal role based access control.
Authors: Uzun, Emre1, Atluri, Vijayalakshmi1, Vaidya, Jaideep1, Sural, Shamik2, Ferrara, Anna Lisa3, Parlato, Gennaro4, Madhusudan, P.5
Source: Journal of Computer Security. 2014, Vol. 22 Issue 6, p961-996. 36p.
Subjects: Computer access control, Computer security research, Electronic information resources, Access control, Access control of computer networks, Electronic authentication
Abstract: Providing restrictive and secure access to resources is a challenging and socially important problem. Among the many formal security models, Role Based Access Control (RBAC) has become the norm in many of today's organizations for enforcing security. For every model, it is necessary to analyze and prove that the corresponding system is secure. Such analysis helps understand the implications of security policies and helps organizations gain confidence on the control they have on resources while providing access, and devise and maintain policies.In this paper, we consider security analysis for the Temporal RBAC (TRBAC), one of the extensions of RBAC. The TRBAC considered in this paper allows temporal restrictions on roles themselves, user-permission assignments (UA), permission-role assignments (PA), as well as role hierarchies (RH). Towards this end, we first propose a suitable administrative model that governs changes to temporal policies. Then we propose our security analysis strategy, that essentially decomposes the temporal security analysis problem into smaller and more manageable RBAC security analysis sub-problems for which the existing RBAC security analysis tools can be employed. We then evaluate them from a practical perspective by evaluating their performance using simulated data sets. [ABSTRACT FROM AUTHOR]
Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 99988665
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Security analysis for temporal role based access control.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Uzun%2C+Emre%22">Uzun, Emre</searchLink><relatesTo>1</relatesTo><br /><searchLink fieldCode="AR" term="%22Atluri%2C+Vijayalakshmi%22">Atluri, Vijayalakshmi</searchLink><relatesTo>1</relatesTo><br /><searchLink fieldCode="AR" term="%22Vaidya%2C+Jaideep%22">Vaidya, Jaideep</searchLink><relatesTo>1</relatesTo><br /><searchLink fieldCode="AR" term="%22Sural%2C+Shamik%22">Sural, Shamik</searchLink><relatesTo>2</relatesTo><br /><searchLink fieldCode="AR" term="%22Ferrara%2C+Anna+Lisa%22">Ferrara, Anna Lisa</searchLink><relatesTo>3</relatesTo><br /><searchLink fieldCode="AR" term="%22Parlato%2C+Gennaro%22">Parlato, Gennaro</searchLink><relatesTo>4</relatesTo><br /><searchLink fieldCode="AR" term="%22Madhusudan%2C+P%2E%22">Madhusudan, P.</searchLink><relatesTo>5</relatesTo>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Journal+of+Computer+Security%22">Journal of Computer Security</searchLink>. 2014, Vol. 22 Issue 6, p961-996. 36p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Computer+access+control%22">Computer access control</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security+research%22">Computer security research</searchLink><br /><searchLink fieldCode="DE" term="%22Electronic+information+resources%22">Electronic information resources</searchLink><br /><searchLink fieldCode="DE" term="%22Access+control%22">Access control</searchLink><br /><searchLink fieldCode="DE" term="%22Access+control+of+computer+networks%22">Access control of computer networks</searchLink><br /><searchLink fieldCode="DE" term="%22Electronic+authentication%22">Electronic authentication</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Providing restrictive and secure access to resources is a challenging and socially important problem. Among the many formal security models, Role Based Access Control (RBAC) has become the norm in many of today's organizations for enforcing security. For every model, it is necessary to analyze and prove that the corresponding system is secure. Such analysis helps understand the implications of security policies and helps organizations gain confidence on the control they have on resources while providing access, and devise and maintain policies.In this paper, we consider security analysis for the Temporal RBAC (TRBAC), one of the extensions of RBAC. The TRBAC considered in this paper allows temporal restrictions on roles themselves, user-permission assignments (UA), permission-role assignments (PA), as well as role hierarchies (RH). Towards this end, we first propose a suitable administrative model that governs changes to temporal policies. Then we propose our security analysis strategy, that essentially decomposes the temporal security analysis problem into smaller and more manageable RBAC security analysis sub-problems for which the existing RBAC security analysis tools can be employed. We then evaluate them from a practical perspective by evaluating their performance using simulated data sets. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=99988665
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.3233/JCS-140510
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 36
        StartPage: 961
    Subjects:
      – SubjectFull: Computer access control
        Type: general
      – SubjectFull: Computer security research
        Type: general
      – SubjectFull: Electronic information resources
        Type: general
      – SubjectFull: Access control
        Type: general
      – SubjectFull: Access control of computer networks
        Type: general
      – SubjectFull: Electronic authentication
        Type: general
    Titles:
      – TitleFull: Security analysis for temporal role based access control.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Uzun, Emre
      – PersonEntity:
          Name:
            NameFull: Atluri, Vijayalakshmi
      – PersonEntity:
          Name:
            NameFull: Vaidya, Jaideep
      – PersonEntity:
          Name:
            NameFull: Sural, Shamik
      – PersonEntity:
          Name:
            NameFull: Ferrara, Anna Lisa
      – PersonEntity:
          Name:
            NameFull: Parlato, Gennaro
      – PersonEntity:
          Name:
            NameFull: Madhusudan, P.
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 12
              Text: 2014
              Type: published
              Y: 2014
          Identifiers:
            – Type: issn-print
              Value: 0926227X
          Numbering:
            – Type: volume
              Value: 22
            – Type: issue
              Value: 6
          Titles:
            – TitleFull: Journal of Computer Security
              Type: main
ResultId 1