Abstract
SystemsRole-based access control (RBAC) has been widely used in information systems including so-called critical systems. Access control models describe the frameworks that dictate permissions. The RBAC model is generally static, ie., access control decisions are: Grant or deny. This model is effective in normal situations. In other situations, such as exceptions or emergencies, flexible access control is required. In order to increase the flexibility of access control, the concept of obligation has been proposed. Obligations are requirements to be fulfilled in order to execute permission decisions. The purpose of this article is to produce a flexible model which uses obligations to manage exception situations. Our model increases the flexibility of the RBAC model. It allows to assign permissions dynamically.For illustration, Anderson's clinical information system is used. Finally, Alloy is used to analyze the validity of the proposed model.
Author supplied keywords
Cite
CITATION STYLE
Bouadjemi, A., & Abdi, M. K. (2021). Towards An Extension Of RBAC Model. International Journal of Computing and Digital Systems, 10(1), 1145–1155. https://doi.org/10.12785/ijcds/1001103
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.