arrow
返回

A Dynamic Access Control Model Using Authorising Workflow and Task-Role-Based Access Control

delete2019-01-01
delete45
delete
OA
AI
M
Mumina Uddin
S
Shareeful Islam *
A
Ameer Al-Nemrat
DOI:10.1109/ACCESS.2019.2947377delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Access control is fundamental and prerequisite to govern and safeguard information assets within an organisation. Organisations generally use web enabled remote access coupled with applications access distributed on the various networks facing various challenges including increase operation burden, monitoring issues due to the dynamic and complex nature of security policies for access control. The increasingly dynamic nature of collaborations means that in one context a user should have access to sensitive information and not applicable for another context. The current access control models are static and lack of Dynamic Segregation of Duties (SoD), Task instance level of Segregation and decision making in real time. This paper addresses the limitations and supports access management in borderless network environment with dynamic SoD capability at real time access control decision making and policy enforcement. This research makes three contributions: i) Defining an Authorising Workflow Task Role Based Access Control using the existing task and workflow concepts. It integrates the dynamic SoD considering the task instance restriction to ensure overall access governance and accountability. It enhances the existing access control models such as RBAC by dynamically granting users access right and providing Access governance. ii) Extended the OASIS standard of XACML policy language to support the dynamic access control requirements and enforce the access control rules for real time decision making to mitigate risk relating to access control such as escalation of privilege in broken access control and insufficient logging and monitoring iii) The model is implemented using open source Balana policy engine to demonstrate its applicability to a real industrial use case from a financial institution. The results show that, AW-TRBAC is scalable consuming relatively large number of complex request and able to meet the requirements of dynamic access control characteristics.
Keyword:
Identity and access management
role based access control
extensible access control markup language
attribute access control
dynamic segregation of duties
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

U
University of East London
学者数:
1.1K
论文数: 1.1K
被引数: 1.0K
引用论文

引用论文

The role of the adversary model in applied security research
err2019-03-01
err71
PREAI
errDo, Quang; Martini, Ben; Choo, Kim-Kwang Raymond
err分享
err收藏
Emergency department antimicrobial use in a low-resource setting: results from a retrospective observational study at a referral hospital in Liberia
err2022-04-18
err0
errOAAI
errSojung Yi; Anu Ramachandran; Lane Epps; Alex Mayah; Taylor W Burkholder; Michael Senyu Jaung; Ahson Haider; Paul Whesseh; John Shakpeh; Kayla Enriquez; Corey Bills
err分享
err收藏
学者 查看更多内容