Interoperable Role-Based Access Control (IRBAC) 2000 model can be used to accomplish security interoperation between two or more administrative domains via role association and dynamic role translation. However, Static Separation of Duties (SSoD) is not considered in the IRBAC 2000 model, so the problem of inter-domain static mutual exclusive roles constraints violation can arise. This paper proposes a novel method based on colored Petri nets to model and analyze IRBAC 2000 model so as to detect static mutual exclusive roles (SMER) constraints violation. The necessary and sufficient conditions for SMER constraints violation in the IRBAC 2000 model are demonstrated. A graphical detection model based on Colored Petri net of SMER constraints violation is presented and then a more complicated case study is used to illustrate the efficiency of the proposed model. Moreover, some prerequisites for avoiding SMER constraints violation and guaranteeing the model security while adding new role association or user-role assignment are also discussed, analyzed and detailed based on colored petri net model in this paper.
목차
Abstract 1. Introduction 2. Preliminaries 2.1. IRBAC2000 Model 2.2. SMER Constraints Violation 3. Colored Petri Nets and Detection Model 3.1. Some Definitions for CPN 3.2. CPN Model of SMER Constraints Violation Detection 3.3. Detection Approach 4. Prerequisite 5. Conclusions References
키워드
Interoperationstatic separation of dutiesstatic mutual exclusive rolesdynamic role translationcolored Petri netsprerequisites
저자
Meng Liu [ Computer Application Research Center, Harbin Institute of Technology Shenzhen Graduate School, Shenzhen 518055, China, School of Mechanical, Electrical and Information Engineering, Shandong University, Weihai 264209, China ]
The corresponding author
Xuan Wang [ Computer Application Research Center, Harbin Institute of Technology Shenzhen Graduate School, Shenzhen 518055, China ]
보안공학연구지원센터(IJSIA) [Science & Engineering Research Support Center, Republic of Korea(IJSIA)]
설립연도
2006
분야
공학>컴퓨터학
소개
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업
간행물
간행물명
International Journal of Security and Its Applications
간기
격월간
pISSN
1738-9976
수록기간
2008~2016
등재여부
SCOPUS
십진분류
KDC 505DDC 605
이 권호 내 다른 논문 / International Journal of Security and Its Applications Vol.8 No.1