A Novel Permission Hierarchy for RBAC for Dealing with SoD in MAC Models
A Novel Permission Hierarchy for RBAC for Dealing with SoD in MAC Models
dc.contributor.author | Veloudis, Simeon | |
dc.contributor.author | Nissanke, Nimal | |
dc.date.accessioned | 2022-04-05T19:38:42Z | |
dc.date.available | 2022-04-05T19:38:42Z | |
dc.date.issued | 2016-04 | |
dc.description.abstract | Separation of duty (SoD) is a fundamental principle of computer security that has not been addressed sufficiently in multi-level security (MLS) mandatory access control (MAC) models, as realized through the adoption of the Bell-LaPadula (BLP) model. This is due to the lack of means at present to express SoD constraints in MAC. The primary objective of this paper is to overcome this but within a framework that allows for rigour and linguistic features to express SoD constraints, while retaining the core security properties of BLP, namely the Simple Security Property and ★-Property. To this end, we propose a formal framework which bridges the BLP model with the more general hierarchical role-based access control (RBAC) model. Our framework is based on a hierarchy of permissions that is founded on a novel concept of permission capacity, determined on the basis of the security levels that characterize objects in MLS models. Such a hierarchy naturally provides a solid basis for defining role seniority and deriving a hierarchical ordering on roles within MLS models. SoD constraints are expressed by means of conflicting permissions that give rise to mutually exclusive roles. | |
dc.identifier.citation | Simeon Veloudis, Nimal Nissanke, A Novel Permission Hierarchy for RBAC for Dealing with SoD in MAC Models, The Computer Journal, Volume 59, Issue 4, April 2016, Pages 462–492 | |
dc.identifier.other | https://doi.org/10.1093/comjnl/bxv060 | |
dc.identifier.uri | https://s455778.name-servers.gr/handle/123456789/40 | |
dc.language.iso | en | |
dc.publisher | Oxford Academic | |
dc.title | A Novel Permission Hierarchy for RBAC for Dealing with SoD in MAC Models | |
dc.type | Article | |
dspace.entity.type |
Files
Original bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- bxv060.pdf
- Size:
- 504.38 KB
- Format:
- Adobe Portable Document Format
- Description:
License bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- license.txt
- Size:
- 1.71 KB
- Format:
- Item-specific license agreed to upon submission
- Description: