The aim of this work is to give a formal foundation to the notion of role-based access control through the introduction of a new model and the formal specification of its semantics. The proposed model takes into account all the main topics currently under discussion in this area, including constraints and separation of duties. Moreover, it is suitable both for conceptual design purpose and direct implementation within real systems.
Index Terms:
role-based access control, security constraints
Citation:
Luigi Giuri, Pietro Iglio, "A Formal Model for Role-Based Access Control with Constraints," csfw, pp.136, Ninth IEEE Computer Security Foundations Workshop, 1996