2000Unpublished venueOpen access

Role delegation in role-based access control

Sang-Yeob Na, Suh-Hyun Cheon

Open full text 70 citations

Abstract

In distributed-computing environments, applications or users have to share resources and communicate with each other to perform their jobs more efficiently.For better performance, it is important to keep resources and the information integrity from the unexpected use by unauthorized user.Therefore, there is a strong demand for the authentication and the access control of distributed-shared resources.Nowadays, three kinds of access control, discretionary access control (DAC) mandatory access control (MAC) and role-based access control (RBAC) have been proposed.In RBAC, there are role hierarchies in which a senior role can perform the permission of a junior role.However, it is sometimes necessary for a junior role to perform a senior role's permission, which is not allowed basically by a junior role.In this paper, we will propose a role delegation method, consisting of a role delegation server, and a role delegation protocols.We divide the delegation into two by the triggered object: active delegation and passive delegation.Consequently, a junior role can gain a senior role's permissions.

Open-access reader

About this research paper

What this paper is about

In distributed-computing environments, applications or users have to share resources and communicate with each other to perform their jobs more efficiently.For better performance, it is important to keep resources and the information integrity from the unexpected use by unauthorized user.Therefore, there is a strong demand for the authentication and the access control of distributed-shared resources.Nowadays, three kinds of access control, discretionary access control (DAC) mandatory access control (MAC) and role-based access control (RBAC) have been proposed.In RBAC, there are role hierarchies in which a senior role can perform the permission of a junior role.However, it is sometimes necessary for a junior role to perform a senior role's permission, which is not allowed basically by a junior role.In this paper, we will propose a role delegation method, consisting of a role delegation server, and a role delegation protocols.We divide the delegation into two by the triggered object: active delegation and passive delegation.Consequently, a junior role can gain a senior role's permissions.

Why it matters

OpenAlex reports 70 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

In distributed-computing environments, applications or users have to share resources and communicate with each other to perform their jobs more efficiently.For better performance, it is important to keep resources and the information integrity from the unexpected use by unauthorized user.Therefore, there is a strong demand for the authentication and the access control of distributed-shared resources.Nowadays, three kinds of access control, discretionary access control (DAC) mandatory access control (MAC) and role-based access control (RBAC) have been proposed.In RBAC, there are role hierarchies in which a senior role can perform the permission of a junior role.However, it is sometimes necessary for a junior role to perform a senior role's permission, which is not allowed basically by a junior role.In this paper, we will propose a role delegation method, consisting of a role delegation server, and a role delegation protocols.We divide the delegation into two by the triggered object: active delegation and passive delegation.Consequently, a junior role can gain a senior role's permissions.

Key concepts: Delegation, Citation, Computer science, Library science, Role-based access control, Computer security, Access control, Operations research

Related papers

Back to paper searchBrowse research topicsOriginal source
Role delegation in role-based access control — Research Paper | ScholarLens