کد مقاله | کد نشریه | سال انتشار | مقاله انگلیسی | نسخه تمام متن |
---|---|---|---|---|
456381 | 695706 | 2016 | 10 صفحه PDF | دانلود رایگان |

The traditional role-based access control (RBAC) model is typically static, i.e., permissions are granted based on a policy that seldom changes. A more flexible support for access control is needed in certain scenarios (such as disaster management). The break the glass RBAC (BTG-RBAC) model is an RBAC model with the break-glass technique, which enables the violation of a predetermined policy in exceptional situations. However, the BTG-RBAC model is unable to provide adequate flexibility in the system. This paper proposes a new independent mechanism, termed transformation, which can change the user assignment to achieve dynamic changes in user permissions. The system should alert users when their permission is changed. Thus, this study integrates transformation with the BTG-RBAC model to create a new model called the Ts-RBAC model. The Ts-RBAC model maintains the safety ensured by the BTG-RBAC model and improves the flexibility of the system.
Journal: Computers & Security - Volume 60, July 2016, Pages 52–61