Abstract

The generalized temporal role-based access control (GTRBAC) model provides a comprehensive set of temporal constraint expressions which can facilitate the specification of fine-grained time-based access control policies. However, the issue of the expressiveness and usability of this model has not been previously investigated. In this paper, we present an analysis of the expressiveness of the constructs provided by this model and illustrate that its constraints-set is not minimal. We show that there is a subset of GTRBAC constraints that is sufficient to express all the access constraints that can be expressed using the full set. We also illustrate that a nonminimal GTRBAC constraint set can provide better flexibility and lower complexity of constraint representation. Based on our analysis, a set of design guidelines for the development of GTRBAC-based security administration is presented.

Journal
IEEE Transactions on Professional Communication
Published
2005-02-01
DOI
10.1109/tdsc.2005.18
CompPile
Open Access
Closed
Topics
Export

Citation Context

Cited by in this index (0)

No articles in this index cite this work.

References (28)

  1. 10.1145/382912.382913
  2. 10.1145/504909.504912
  3. Role Based Access Control for the World Wide Web
  4. 10.1145/293910.293151
  5. 10.1145/501978.501979
Show all 28 →
  1. 10.1145/300830.300837
  2. 10.1109/MC.2004.1297300
  3. 10.1145/1108906.1108909
  4. 10.1145/373256.373258
  5. An Examination of Federal and Commercial Access Control Policy Needs
  6. 10.1007/978-3-540-24741-8_3
  7. 10.1145/270152.270176
  8. 10.1145/359205.359224
  9. 10.1109/MIC.2004.53
  10. 10.1109/2.901169
  11. 10.1145/507711.507724
  12. 10.1109/TKDE.2005.1
  13. 10.1145/567331.567336
  14. 10.1145/775412.775421
  15. An Efficient Symbolic Representation of Periodic Time
  16. 10.1145/300830.300832
  17. 10.1145/354876.354878
  18. 10.1145/383775.383777
  19. 10.1145/286884.286891
  20. Separation of Duties in Computerized Information Systems
    Database Security IV: Status and Prospects
  21. 10.1109/2.485845
  22. 10.1109/CSFW.1997.596811
  23. 10.1109/ENABL.2001.953414