Role based access control (RBAC) has been widely adopted in industrial and government. However RBAC is only suitable for closed enterprise environment. With modern Internet based application, collaboration and sharing among multiple organizations become essential and RBAC is no longer sufficient. Role mapping has been the solutions to deal with multiple domains, where the roles in the hierarchy of one organization are mapped to the roles in the hierarchy of another organization. But role mapping can be a tedious task for the security officers if it is done fully manually. Yet, performing role mapping automatically incur security risks. In this paper, we introduce a semi-automated role mapping process, where promising role mappings are generated automatically and recommended to the security officer(s). The security officers then approve or modify the recommended role mappings. We present a method for automatically generate role mappings based on the similarities of the roles in two role hierarchies. We use an example to illustrate our approach and show its feasibility.
목차
Abstract 1. Introduction 2. A Running Example 3. Semi-Automated Role Mapping Process 3.1.The Role Mapping Manager 3.2. The Role Mapping Process 3.3. On-the-Fly Role Mapping 4. Automated Role Mapping Analysis and Recommendation 4.1. OWL-Based Role Specification Model 4.2. Concept Extraction 4.3. Similarity Between Roles 4.4. Role Mapping Recommendation 4.5. Modify Role Hierarchy for Role Mapping 5. Conclusions References
Feng wang [ School of Mathematicsand Statistics Science, Ludong University,Yan Tai, China / Key Laboratory of Language Resource Development and Application of Shandong Province, Yan Tai ]
Lei Cui [ Information Engineering Department,YanTai Vocational College, Yanai, China ]
Yizhen Wang [ Tilburg University, Tilburg, the Netherlands ]
Xinjiang Wei [ School of Mathematicsand Statistics Science, Ludong University,Yan Tai, China / Key Laboratory of Language Resource Development and Application of Shandong Province, Yan Tai ]
보안공학연구지원센터(IJDTA) [Science & Engineering Research Support Center, Republic of Korea(IJDTA)]
설립연도
2006
분야
공학>컴퓨터학
소개
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업
간행물
간행물명
International Journal of Database Theory and Application
간기
격월간
pISSN
2005-4270
수록기간
2008~2016
십진분류
KDC 505DDC 605
이 권호 내 다른 논문 / International Journal of Database Theory and Application Vol.9 No.10