Activating appropriate roles for a session in the role-based access control (RBAC) model has become challenging because of the so-called role explosion. In this paper, factors and issues related to user-driven role management are analysed, and a session role activation (SRA) problem based on reasonable assumptions is proposed to describe the problem of such role management. To solve the SRA problem, we propose an extended RBAC model with context-based role filtering. When a session is created, context conditions are used to filter roles that do not need to be activated for the session. This significantly reduces the candidate roles that need to be reviewed by the user, and aids the user in rapidly activating the appropriate roles. Simulations are carried out, and the results show that the extended RBAC model is effective in filtering the roles that are unnecessary for a session by using predefined context conditions. The extended RBAC model is also implemented in the Apache Shiro framework, and the modifications to Shiro are described in detail.
CITATION STYLE
Liu, G., Zhang, R., Wan, B., Ji, S., & Tian, Y. (2020). Extended role-based access control with context-based role filtering. In KSII Transactions on Internet and Information Systems (Vol. 14, pp. 1263–1279). Korean Society for Internet Information. https://doi.org/10.3837/tiis.2020.03.019
Mendeley helps you to discover research relevant for your work.