Rbac Session Management With Ticket

Feng Li,Jin Ma,Jian-Hua Li
2006-01-01
Abstract:RBAC (Role-Based Access Control) is one of the most popular access control models to specify and reinforce security polices. Current researches on RBAC mainly focus on the frameworks, the enhanced models. and constraints description that based on RBAC. However, the cooperative methods between applications and access control models are rarely mentioned. This paper raises a dynamic session management model for PBAC. Ticket concept presents to describe and enhance session content in the proposed model. Taking ticket as the carrier, authorization information can be stored, transferred, and supervised easily. In addition, ticket is taken as a standard interface for application authorization due to the uniform structure. Ticket pool is provided to manage the tickets where advanced constraints can be deployed. Differ from the DSD (Dynamic Separation of Duty), it can be also extended to support advanced constraints, such as task based operations or access control in a distributed environment. The new model improves the flexibility as well as the security, and formalizes the application implementation of RBAC. It also supports the existing RBAC constraints as well.
What problem does this paper attempt to address?