Formal Description for an Object-Oriented Role-based Access Control Model

Chungen Xu, Sheng Gong
2009 Computer and Information Science  
Role-based access control(RBAC) is a promising technology for managing and enforcing security in large-scale enterprise-wide system, and we were motivated by the need to manage and enforce the strong access control technology of RBAC in large-scale Web environments. Majority of traditional access control models were passive data-protections, which were not suitable for large and complex multi-user interactive applications. In this paper, we develop a general model to control users' behaviors
more » ... ed on their roles actively, and proposes a framework of well-defined Formal Description for developers to build application-level access control based on users' roles. It ensure that each role is configured with consistent privileges, each actor is authorized to proper roles and then each actor can activate and play his authorized roles without interest conflicts. These formal specifications are consistent and inferable, complete and simplified, abundant and scalable for diversified multi-user applications.
doi:10.5539/cis.v2n2p68 fatcat:4f7hfix5prbg7dqstw6xdo45ky