Formal Specification for Object-oriented Model of Role-based Access Control

许春根,严悍,刘凤玉
DOI: https://doi.org/10.3969/j.issn.1000-1220.2003.05.015
2003-01-01
Abstract:Access control is significant and intricate component in a large and complex multi-user distributed system. Role based Access Control (RBAC) has been a mainstream security mechanism and object technology has been an effective approach to deal with complexity presently. An object-oriented and formal access control model is imperative for developers to design security mechanism of systems and for users to.perform their duties securely and efficiently. However, existed access control models were mostly informal and non-Object-Oriented. Therefore, this paper proposes a formal and Object-Oriented model for RBAC in Unified Modeling Language (UML). The model is constructed simply and provides consistent and inferable constraint specifications for developers to design access control of large and complex systems.
What problem does this paper attempt to address?