Constraint access control for direct authorization
Wei-li Han,Xing-dong Shi,Yin-sheng Li
DOI: https://doi.org/10.1109/CSCWD.2005.194147
2005-01-01
Abstract:Constraint is an important aspect of role-based access control (RBAC) and is sometimes considered to be the principal motivation for RBAC. Current major RBAC systems generally do not support constraints, or support constraints only in pure RBAC mode. But a few practical systems need direct authorization to ease permission administration. To achieve this purpose, this paper probes into the problem of constraints in mixed access control. This mainly adopts RBAC and supports direct authorization. Firstly, the paper discusses constraints in mixed access control. In this part, the paper presents the concept of permission constraint, and analyzes the relationships between permission constraint and role constraint. Secondly, some key properties of constraints are identified and proofed formally. Finally, the paper introduces permissions administration in a drawing management module of an enterprise information system, as a case to study the problem of constraints in mixed access control.