An improved approach towards the model of IRBAC2000

Zhensong Liao,Hai Jin,Weizhong Qiang
DOI: https://doi.org/10.3321/j.issn:1671-4512.2005.z1.082
2005-01-01
Abstract:According to the security pitfalls of IRBAC2000 model, an improved approach is proposed to deal with the problems of role intersection and role conflicts. The approach discards role hierarchy, changes it into the directory structure. The difference between roles appears on the map from role to privilege. Meanwhile, the improved approach allows roles to have an association across various secure domains, however, the role transitive is disallowed. This paper still gives a detailed analysis of the improved approach on security and feasibility. The experimental results show that the improved approach has a good practicability and operation flexibility.
What problem does this paper attempt to address?