Ts-RBAC: A RBAC Model with Transformation

Gang Liu,Runnan Zhang,Huimin Song,Can Wang,Jinhui Liu,Aijun Liu
DOI: https://doi.org/10.1016/j.cose.2016.03.006
IF: 5.105
2016-01-01
Computers & Security
Abstract:The traditional role-based access control (RBAC) model is typically static, i.e., permissions are granted based on a policy that seldom changes. A more flexible support for access control is needed in certain scenarios (such as disaster management). The break the glass RBAC (BTG-RBAC) model is an RBAC model with the break-glass technique, which enables the violation of a predetermined policy in exceptional situations. However, the BTG-RBAC model is unable to provide adequate flexibility in the system. This paper proposes a new independent mechanism, termed transformation, which can change the user assignment to achieve dynamic changes in user permissions. The system should alert users when their permission is changed. Thus, this study integrates transformation with the BTG-RBAC model to create a new model called the Ts-RBAC model. The Ts-RBAC model maintains the safety ensured by the BTG-RBAC model and improves the flexibility of the system.
What problem does this paper attempt to address?