Security analysis of role based access control models using colored petri nets and CPNtools

19Citations
Citations of this article
14Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Several adVanced Role based access control (RBAC) models have been developed supporting specific features (i.e.: role hierarchy, separation of duty) to achieve high flexibility. However, integrating additional features also increases their design complexity, and consequently the opportunity for mistakes that may cause information to flow to inappropriate destinations. In this paper, we present a formal technique to model and analyze RBAC using Colored Petri nets (CP-nets) and CPNtools1 for editing and analyzing CP-nets. Our purpose is to elaborate a CP-net model which describes generic access control structures based on an RBAC policy. The resulting CP-net model can be then composed with different context-specific aspects depending on the application. A significant benefit of CP-nets and, particularly, CPNtool s is to proviDe a graphical representation and an analysis framework that can be used by security administrators to understand why some permissions are granted or not and to detect whether security constraints are violated. ©Springer-Verlag Berlin Heidelberg 2009.

Cite

CITATION STYLE

APA

Rakkay, H., & Boucheneb, H. (2009). Security analysis of role based access control models using colored petri nets and CPNtools. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 5430 LNCS, pp. 149–176). https://doi.org/10.1007/978-3-642-01004-0_9

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free