Title
Multi-session Separation of Duties (MSoD) for RBAC
Abstract
Separation of duties (SoD) is a key security requirement for many business and information systems. Role Based Access Controls (RBAC) is a relatively new paradigm for protecting information systems. In the ANSI standard RBAC model both static and dynamic SoD are defined. However, static SoD policies assume that the system has full control over the assignment of all roles to users, whilst dynamic SoD policies assume that conflicts of interest can only arise during the simultaneous activation of a user's roles. Unfortunately neither of these assumptions hold true in dynamic virtual organisations (VOs), or in business processes that span multiple user sessions, or where users only partially disclose their roles at each session. In this paper we propose multi-session SoD (MSoD) policies for business processes which include multiple tasks enacted by multiple users over many user access control sessions. We explore the means to define MSoD policies in RBAC via multi-session mutually exclusive roles (MMER) and multi-session mutually exclusive privileges (MMEP). We propose an approach to expressing MSoD policies in XML and enforcing MSoD policies in a policy controlled RBAC infrastructure. Finally, we describe how we have implemented MSoD policies in the PERMIS Privilege Management Infrastructure
Year
DOI
Venue
2007
10.1109/ICDEW.2007.4401062
ICDE Workshops
Keywords
Field
DocType
rbac infrastructure,static sod policy,business process,information system,multi-session separation,msod policy,whilst dynamic sod policy,multi-session sod,dynamic virtual organisation,ansi standard rbac model,dynamic sod,authorisation,access control,rbac,information systems,management information systems,history,privilege management infrastructure,separation of duty,computer programming,xml,information security,control systems,role based access control
Information system,Data mining,XML,Business process,Computer security,Computer science,Role-based access control,Access control,Privilege Management Infrastructure,PERMIS,Separation of duties,Database
Conference
Volume
Issue
ISSN
null
null
1943-2895
ISBN
Citations 
PageRank 
978-1-4244-0832-0
8
0.76
References 
Authors
8
5
Name
Order
Citations
PageRank
David W. Chadwick179980.70
Wensheng Xu2234.56
Sassa Otenko31059.08
Romain Laborde416228.88
Bassem Nasser5464.25