Authors
David F Ferraiolo, Ravi Sandhu, Serban Gavrila, D Richard Kuhn, Ramaswamy Chandramouli
Publication date
2001/8/1
Journal
ACM Transactions on Information and System Security (TISSEC)
Volume
4
Issue
3
Pages
224-274
Publisher
ACM
Description
In this article we propose a standard for role-based access control (RBAC). Although RBAC models have received broad support as a generalized approach to access control, and are well recognized for their many advantages in performing large-scale authorization management, no single authoritative definition of RBAC exists today. This lack of a widely accepted model results in uncertainty and confusion about RBAC's utility and meaning. The standard proposed here seeks to resolve this situation by unifying ideas from a base of frequently referenced RBAC models, commercial products, and research prototypes. It is intended to serve as a foundation for product development, evaluation, and procurement specification. Although RBAC continues to evolve as users, researchers, and vendors gain experience with its application, we feel the features and components proposed in this standard represent a …
Total citations
20022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024391381862433042983252732732302242011661831491491291058867626038
Scholar articles
DF Ferraiolo, R Sandhu, S Gavrila, DR Kuhn… - ACM Transactions on Information and System Security …, 2001