Authors
Sylvia Osborn, Ravi Sandhu, Qamar Munawer
Publication date
2000/5/1
Journal
ACM Transactions on Information and System Security
Volume
3
Issue
2
Pages
85-106
Publisher
Association for Computing Machinery, Inc, One Astor Plaza, 1515 Broadway, New York, NY, 10036-5701, USA,
Description
Access control models have traditionally included mandatory access control (or lattice-based access control) and discretionary access control. Subsequently, role-based access control has been introduced, along with claims that its mechanisms are general enough to simulate the traditional methods. In this paper we provide systematic constructions for various common forms of both of the traditional access control paradigms using the role-based access control (RBAC) models of Sandhu et al., commonly called RBAC96. We see that all of the features of the RBAC96 model are required, and that although for the manatory access control simulation, only one administrative role needs to be assumed, for the discretionary access control simulations, a complex set of administrative roles is required.
Total citations
20002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320241014355465617079606252574042454931352623211715137
Scholar articles
S Osborn, R Sandhu, Q Munawer - ACM Transactions on Information and System Security …, 2000