arrow
返回

Data flow security in Role-based access control

delete2025-05-01
delete0
delete
OA
AI
L
Luigi Logrippo *
DOI:10.1016/j.jisa.2025.103997delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
We show how data security concepts such as data flow, secrecy (or confidentiality) and integrity can be defined for RBAC, Role-Based Access Control. In contrast to the prevailing literature that uses a lattice model to express such concepts, we demonstrate the use of a partial order model that is more general. This is done by using the concepts of partial order of equivalence classes and of security labels that can be associated with RBAC subjects and objects and determine their mutual data flows, as well as their secrecy and integrity properties. Our model allows to reason on RBAC configurations with different assignments of roles to subjects. On the converse, we demonstrate a method for obtaining RBAC configurations from data security requirements or security label assignments. These results are supported by a proof showing that three methods for defining data flow: by access control matrices or lists, by labels and by roles, are equivalent and mutually convertible by efficient algorithms. We show how RBAC state changes, or reconfigurations can be defined in this framework, and what are the effects of elementary reconfigurations on data flow, secrecy and integrity of data.
Keyword:
RBAC
Role-based access control, data flow
control
Data security
Data secrecy
Data confidentiality
Data integrity
Multi-level access control
Mandatory access control
Security labeling
Design for security
Role mining

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
1.9K
被引数:
4.9K

机构

U
university of quebec
学者数:
2.0W
论文数: 1.9W
被引数: 19
引用论文

引用论文

暂无论文信息