Download presentation
Presentation is loading. Please wait.
Published byMichelle Lane Modified over 11 years ago
2
Role Activation Hierarchies Ravi Sandhu George Mason University
3
RBAC96 ROLES USER-ROLE ASSIGNMENT PERMISSION-ROLE ASSIGNMENT USERSPERMISSIONS... SESSIONS ROLE HIERARCHIES CONSTRAINTS
4
ROLE HIERARCHIES u Inheritance hierarchies l permission inheritance l user inheritance u Activation hierarchies l role membership versus role activation
5
EXAMPLE ROLE HIERARCHY INTERPRETATIONS Employee (E) Engineering Department (ED) Project Lead 1 (PL1) Engineer 1 (E1) Production 1 (P1) Quality 1 (Q1) Director (DIR) Project Lead 2 (PL2) Engineer 2 (E2) Production 2 (P2) Quality 2 (Q2) PROJECT 2PROJECT 1
6
ALTERNATIVES u separate inheritance and activation hierarchies l this paper u single inheritance and activation hierarchy l most common approach, including RBAC96 u activation hierarchy only, no inheritance l alternative identified in NIST RBAC model u inheritance hierarchy only, no activation hierarchy l does not seem to be useful
7
LBAC: LIBERAL *-PROPERTY H L M1M2 ReadWrite -+ +-
8
LBAC: LIBERAL *-PROPERTY DUAL ROLE SIMULATION HR LR M1RM2R LW HW M1WM2W Read Write - +
9
LBAC: STRICT *-PROPERTY H L M1M2 ReadWrite - +
10
LBAC: STRICT *-PROPERTY DUAL ROLE SIMULATION HR LR M1RM2R LWHWM1WM2W
11
LBAC: STRICT *-PROPERTY SIMULATION BY PRIVATE ROLES HR LR M1RM2R
12
LBAC: STRICT *-PROPERTY SIMULATION BY PRIVATE ROLES HR LR M1RM2R HW LW M1WM2W
13
LBAC: STRICT *-PROPERTY SIMULATION BY PRIVATE ROLES HR LR M1RM2R HW LW M1WM2W
14
DYNAMIC SEPARATION OF DUTIES u Roles in dynamic SOD l cannot have common seniors in role inheritance hierarchy, but l can have common seniors in role activation hierarchy
15
EXAMPLE ROLE HIERARCHY INTERPRETATIONS Employee (E) Engineering Department (ED) Project Lead 1 (PL1) Engineer 1 (E1) Production 1 (P1) Quality 1 (Q1) Director (DIR) Project Lead 2 (PL2) Engineer 2 (E2) Production 2 (P2) Quality 2 (Q2) PROJECT 2PROJECT 1
16
ACTIVATION HIERARCHIES A B D C E A B D C E
17
CONCLUSION u separate inheritance and activation hierarchies l this paper u single inheritance and activation hierarchy l most common approach, including RBAC96 u activation hierarchy only, no inheritance l alternative identified in NIST RBAC model u inheritance hierarchy only, no activation hierarchy l does not seem to be useful
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.