Design and implementation of a CIM-SPL based RBAC policy language

Yanming Cao,Li Pan
DOI: https://doi.org/10.4028/www.scientific.net/AMM.195-196.126
2012-01-01
Applied Mechanics and Materials
Abstract:Since the original CIM-SPL policy language does not support access control policy, the CIM-SPL is extended with the RBAC model in this paper. Then a new CIM-SPL based RBAC policy language is designed and implemented. The syntax specification of the new policy language complies with the original CIM-SPL. So it is quite suitable to describe access control policies for information systems specified by CIM. The implementation framework of the new access control policy language is based on the IETF PDP/PEP approach and is integrated in the Open Pegasus system which is the most widely used open-source software of CIM implementation. At last, a case study of Health Information System is used to demonstrate the flexibility and applicability of the new access control policy language.
What problem does this paper attempt to address?