Using description logic to determine seniority among RB-RBAC authorization rules

Qi Xie,Dayou Liu,Haibo Yu
DOI: https://doi.org/10.1007/11795131_88
2006-01-01
Abstract:Rule-Based RBAC (RB-RBAC) provides the mechanism to dynamically assign users to roles based on authorization rules defined by security policy. In RB-RBAC, seniority levels of rules are also introduced to express domination relationship among rules. Hence, relations among attribute expressions may be quite complex and security officers may perform incorrect or unintended assignments if they are not aware of such relations behind authorization rules. We proposed a formalization of RB-RBAC by description logic. A seniority relation determination method is developed based on description logic reasoning services. This method can find out seniority relations efficiently even for rules without identical syntax structures
What problem does this paper attempt to address?