© 2005 Ravi Sandhu Administrative Scope (continued) (best viewed in slide show mode) Ravi Sandhu Laboratory for Information Security Technology George Mason University
© 2005 Ravi Sandhu 2 RHA Conditions for Four Operations These conditions always apply RHA1 Additional conditions may be imposed RHA2, RHA3, RHA4 These are allowed to be
© 2005 Ravi Sandhu 3 RHA: Add role Y with no children (scope PL1) Y
© 2005 Ravi Sandhu 4 RHA: Insert edge ENG1, Y (scope PL1) Y
© 2005 Ravi Sandhu 5 RHA: Delete edge ENG1, Y (scope PL1) Y outside scope of PL1 so cannot get back to childless Y
© 2005 Ravi Sandhu 6 RHA: Add role Y with no parents (scope PL1) scope of PL1 scope of DIR
© 2005 Ravi Sandhu 7 RHA: Add role Y with no parents (scope PL1) Y scope of PL1 scope of DIR
© 2005 Ravi Sandhu 8 RHA Conditions for Four Operations These conditions always apply RHA1 Additional conditions may be imposed RHA2, RHA3, RHA4 These are allowed to be May not be a good idea, especially for parents
© 2005 Ravi Sandhu 9 RHA3
© 2005 Ravi Sandhu 10 RHA3
© 2005 Ravi Sandhu 11 RHA3: Administrative Scope
© 2005 Ravi Sandhu 12 RHA3 S + (PSO1) S + (DSO)
© 2005 Ravi Sandhu 13 RHA3: PSO1 creates Y S + (PSO1) S + (DSO) Y
© 2005 Ravi Sandhu 14 RHA3: Consistency Constraints
© 2005 Ravi Sandhu 15 RHA4: admin-authority operations
© 2005 Ravi Sandhu 16 RHA4: creation of parentless roles not allowed Forces PSO1 as administrator of X Should be DSO? Eliminated from admin-hierarchy