XACML-based Access Control and RBAC Constraints

Nuermaimaiti·Heilili,LUO Zhen-xing,LIN Zuo-quan
DOI: https://doi.org/10.3969/j.issn.1000-3428.2008.08.007
2008-01-01
Abstract:Constraints are considered to be the principal motivation for Role-Based Access Control(RBAC).This paper analyzes XML based access control language XACML and points out some shortcomings of the XACML profile for RBAC.It provides role enablement authority to extend this profile,in this way,several kinds of constraints of RBAC such as separation of duty constraints and cardinality constraints can be enforced and implemented using XACML.
What problem does this paper attempt to address?