Using RBAC-based Approach to Integrate Access Control Policies in Legacy Systems

LI Han,GUO He,WANG Yu-xin,LU Guo-ji,YANG Yuan-sheng
DOI: https://doi.org/10.3969/j.issn.1002-137x.2011.07.028
2011-01-01
Computer Science
Abstract:Access control whose objective is to ensure the security of accessing to resources in software systems is an essential part for software systems.As access control policies in legacy systems seldom based on roles are represented in various forms,an RBAC-based approach was proposed to integrate these access control policies.The approach maps permission of legacy systems to tasks of integrated system.Based on task trees and transformation rules of access control policy,various access control policies were reorganized in a unified form.Moreover,management rules were provi-ded to achieve further authorization.A case study is demonstrated to depict the proposed approach is a feasible solution to integrate legacy access control policies and introduce RBAC into legacy systems.
What problem does this paper attempt to address?