A Novel Permission Hierarchy for RBAC for Dealing with SoD in MAC Models

dc.contributor.author Veloudis, Simeon
dc.contributor.author Nissanke, Nimal
dc.date.accessioned 2022-04-05T19:38:42Z
dc.date.available 2022-04-05T19:38:42Z
dc.date.issued 2016-04
dc.description.abstract Separation of duty (SoD) is a fundamental principle of computer security that has not been addressed sufficiently in multi-level security (MLS) mandatory access control (MAC) models, as realized through the adoption of the Bell-LaPadula (BLP) model. This is due to the lack of means at present to express SoD constraints in MAC. The primary objective of this paper is to overcome this but within a framework that allows for rigour and linguistic features to express SoD constraints, while retaining the core security properties of BLP, namely the Simple Security Property and ★-Property. To this end, we propose a formal framework which bridges the BLP model with the more general hierarchical role-based access control (RBAC) model. Our framework is based on a hierarchy of permissions that is founded on a novel concept of permission capacity, determined on the basis of the security levels that characterize objects in MLS models. Such a hierarchy naturally provides a solid basis for defining role seniority and deriving a hierarchical ordering on roles within MLS models. SoD constraints are expressed by means of conflicting permissions that give rise to mutually exclusive roles.
dc.identifier.citation Simeon Veloudis, Nimal Nissanke, A Novel Permission Hierarchy for RBAC for Dealing with SoD in MAC Models, The Computer Journal, Volume 59, Issue 4, April 2016, Pages 462–492
dc.identifier.other https://doi.org/10.1093/comjnl/bxv060
dc.identifier.uri https://s455778.name-servers.gr/handle/123456789/40
dc.language.iso en
dc.publisher Oxford Academic
dc.title A Novel Permission Hierarchy for RBAC for Dealing with SoD in MAC Models
dc.type Article
dspace.entity.type
Files
Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
bxv060.pdf
Size:
504.38 KB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed to upon submission
Description: