A state-transfer-based dynamic policy approach for constraints in RBAC

Cheng Zang,Zhongdong Huang,Gang Chen,Jinxiang Dong
DOI: https://doi.org/10.1007/11563952_76
2005-01-01
Abstract:RBAC is widely used in access control field, and this paper proposes an approach to implement dynamic policy transfer on this model. Our approach monitors state-transfers of subjects and transfers policies correspondingly. It holds a finite number of states and a policy transfer set containing the predefined policies. When a state-transfer occurs, an appropriate policy chosen from the policy transfer set will be applied to change the user-role mapping or the role-permission mapping from one to another. This policy transfer not only focuses on the current state, but also takes the previous state into consideration since changing from different state will lead to a different current policy.
What problem does this paper attempt to address?