Model for access control system based on RBAC and GFAC
Wei Jian-xiang
Abstract
Wei Jian-xiang
Abstract
On study of Role-Based Access Control(RBAC)model and Generalized Framework for Access Control(GFAC),the generalized model for access control based on RBAC and GFAC was presented.The characteristics of this model and the control policy were described,in which the group permission,constraint elements and special permission were introduced.Combining techniques of layered authorization,minimizing privileges and role inherited authorization,the RBAC was optimized by enforcing access control on the request.It can figure out the complex access control in the system,and decrease the complexity of the authorization and management of users.The system is configurable and can be maintained easily.Finally,the case of a generalized access control system was given.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
On study of Role-Based Access Control(RBAC)model and Generalized Framework for Access Control(GFAC),the generalized model for access control based on RBAC and GFAC was presented.The characteristics of this model and the control policy were described,in which the group permission,constraint elements and special permission were introduced.Combining techniques of layered authorization,minimizing privileges and role inherited authorization,the RBAC was optimized by enforcing access control on the request.It can figure out the complex access control in the system,and decrease the complexity of the authorization and management of users.The system is configurable and can be maintained easily.Finally,the case of a generalized access control system was given.
Key concepts: Role-based access control, Permission, Access control, Authorization, Computer science, Computer access control, Constraint (computer-aided design), Computer security