Role based access control framework for network enterprises

被引:18
作者
Thomsen, D [1 ]
O'Brien, D [1 ]
Bogle, J [1 ]
机构
[1] Secure Comp Corp, Roseville, MN 55113 USA
来源
14TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS | 1998年
关键词
D O I
10.1109/CSAC.1998.738571
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
A business's success depends on its ability to protect valuable business assets bl an increasingly hostile environment. Protecting information requires a cost, not only irt purchasing security components, but also in ensuring that those security components are properly managed. Role Based Access Control (RBAC) shows promise for making security administration easier thus reducing the cost of managing security components. RBAC provides a convenient la?:er of abstraction by describing access control patterns. This paper presents an RBAC framework comprised of seven abstract layers. Multiple layers allow users to work with a layer they understand. Thus a balance carl be struck between fine grained access control and ease of management, The goal is to provide easy security,management for a wide variety of network applications. The NAPOLEON tool which implements parts of the framework is also described.(1).
引用
收藏
页码:50 / 58
页数:9
相关论文
共 9 条
[1]  
Barkley J., 1995, P 1 ACM WORKSH ROL B, P93
[2]  
ORFALI R, 1998, CLIENT SERVER PROGRA
[3]   Role based access control models [J].
Sandhu, RS ;
Coyne, EJ ;
Feinstein, HL ;
Youman, CE .
COMPUTER, 1996, 29 (02) :38-&
[4]  
SESSIONS R, 1997, COM DCOM MICROSOFTS
[5]  
THOMAS RK, 1997, P 11 ANN IFIP WG 11
[6]  
Thomas RK., 1997, P 2 ACM WORKSH ROL B, P13, DOI DOI 10.1145/266741.266748
[7]  
Thomsen D. J., 1991, Database Security, IV. Status and Prospects: Results of the IFIP WG 11.3 Workshop, P151
[8]  
THOMSEN DJ, 1991, THESIS U MINNESOTA
[9]  
ZURKO ME, 1996, NEW SECURITY PARADIG