Link to the University of Pittsburgh Homepage
Link to the University Library System Homepage Link to the Contact Us Form

A generalized temporal role-based access control model

Joshi, JBD and Bertino, E and Latif, U and Ghafoor, A (2005) A generalized temporal role-based access control model. IEEE Transactions on Knowledge and Data Engineering, 17 (1). 4 - 23. ISSN 1041-4347

[img] Plain Text (licence)
Available under License : See the attached license file.

Download (1kB)

Abstract

Role-based access control (RBAC) models have generated a great interest in the security community as a powerful and generalized approach to security management. In many practical scenarios, users may be restricted to assume roles only at predefined time periods. Furthermore, roles may only be invoked on prespecified intervals of time depending upon when certain actions are permitted. To capture such dynamic aspects of a role, a temporal RBAC (TRBAC) model has been recently proposed. However, the TRBAC model addresses the role enabling constraints only. In this paper, we propose a Generalized Temporal Role-Based Access Control (GTRBAC) model capable of expressing a wider range of temporal constraints. In particular, the model allows expressing periodic as well as duration constraints on roles, user-role assignments, and role-permission assignments. In an interval, activation of a role can further be restricted as a result of numerous activation constraints including cardinality constraints and maximum active duration constraints. The GTRBAC model extends the syntactic structure of the TRBAC model and its event and trigger expressions subsume those of TRBAC. Furthermore, GTRBAC allows expressing role hierarchies and separation of duty (SoD) constraints for specifying fine-grained temporal semantics. © 2005 IEEE.


Share

Citation/Export:
Social Networking:
Share |

Details

Item Type: Article
Status: Published
Creators/Authors:
CreatorsEmailPitt UsernameORCID
Joshi, JBDjjoshi@pitt.eduJJOSHI
Bertino, E
Latif, U
Ghafoor, A
Date: 1 January 2005
Date Type: Publication
Journal or Publication Title: IEEE Transactions on Knowledge and Data Engineering
Volume: 17
Number: 1
Page Range: 4 - 23
DOI or Unique Handle: 10.1109/tkde.2005.1
Schools and Programs: School of Information Sciences > Information Science
Refereed: Yes
ISSN: 1041-4347
Date Deposited: 30 Oct 2012 20:29
Last Modified: 02 Feb 2019 16:55
URI: http://d-scholarship.pitt.edu/id/eprint/16141

Metrics

Monthly Views for the past 3 years

Plum Analytics

Altmetric.com


Actions (login required)

View Item View Item