Scalability Enhanced Active-Passive-integrated Access Control Model

Yanxia Liu
2011-01-01
Computer Integrated Manufacturing Systems
Abstract:The 3-step authorization mechanism based on task classification and role hierarchy integrates two access control paradigms of active and passive ones.But the scalability of the related models was seriously affected by repetitive authorizations among tasks,conflicts among task inheritances along multiple role hierarchies and repetitive expressions of task constraints.To deal with these problems,an enhanced active-passive integrated access control model was proposed.The classification of active/passive tasks was refined through extendable subdivision of role hierarchy,thus many kinds of task assignments could be simplified flexibly.Task generalization based authorization inheritance and constraint coverage mechanisms were introduced to reduce repeatitive authority and constraint among tasks.The basis was provided for automatic constraints simplification by a set of correct semantic overlay rules.Finally,multiple-granularity permission activation mechanism and dynamic exclusions redundancy detecting algorithm was presented to eliminate unnecessary cost in access checking and to compensate efficiency loss brought by scalability enhancing.
What problem does this paper attempt to address?