Publication | Closed Access
Policy contexts: controlling information flow in parameterised RBAC
29
Citations
12
References
2004
Year
Unknown Venue
EngineeringInformation SecuritySoftware EngineeringFormal VerificationPolicy ManagementLogical Access ControlData ScienceAccess ControlSystems EngineeringData ManagementTrusted Operating SystemRbac Policy EnforcementInformation ControlData PrivacyComputer ScienceInformation ManagementMany Rbac ModelsInformation FlowOasis Rbac SystemData SecurityPolicy ContextsAutomated ReasoningFormal MethodsRegulationComputer Security ModelModel-driven Security
Many RBAC models have augmented the fundamental requirement of a role abstraction with features such as parameterised roles and environment-aware policy. We examine the potential for unintentional leakage of information during RBAC policy enforcement, either through the exchange of parameters with external services when checking environmental conditions, or through a policy design which does not appropriately separate policy subsections with different basic purposes. We propose a simple, robust mechanism for handling these problems, and illustrate our approach with a current application of our OASIS RBAC system.
| Year | Citations | |
|---|---|---|
Page 1
Page 1