Detecting Conflict of Permissions in RBAC Model with Semantic Approach

ZHANG Lei,XIANG Hong,HU Haibo
DOI: https://doi.org/10.3778/j.issn.1002-8331.2011.26.022
2011-01-01
Computer Engineering and Applications Journal
Abstract:The RBAC(Role Based Access Control) model separates user with permission logically by introducing role,to make authorization process manageable.However,in the process of generating roles and permissions for authorization,the conflict detection problem has not been well resolved.A method for detecting permission conflicts in RBAC model based on semantic is proposed by adopting description logics to construct knowledge base,to represent RBAC model and reason the relationships of permissions and their conflicts.Thus conflicts of permissions can be detected effectively with reasoning in knowledge base by detecting conflicts when roles are assigned to user,permissions are assigned to role and permissions are assigned to user directly,to ensure consistency and correctness of user permission in RBAC model.
What problem does this paper attempt to address?