Supporting Negative Authorization in Spatiotemporal Role Based Access Control
Samrat Mondal, Shamik Sural
Abstract
Samrat Mondal, Shamik Sural
Abstract
Role based access control (RBAC) has emerged as an effective solution for several access control problems of relevance today. To cope with the growing requirements, core RBAC has been extended over temporal, spatial and spatiotemporal dimensions. The various models developed so far predominantly deal with monotonic policies which allow access only if there is a corresponding positive authorization. However, in many practical situations, there is a need for specifying policies that deny access through negative authorization. The authorization may again depend on different spatiotemporal conditions. In this paper, the notion of user-role-permission (URP) relation is used to incorporate negative authorization in ESTARBAC, one of the existing spatiotemporal RBAC models. The proposed method has been compared with two other existing approaches. We also analyze how negative authorization can facilitate expressing some of the important access control policies relevant for an organization.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Role based access control (RBAC) has emerged as an effective solution for several access control problems of relevance today. To cope with the growing requirements, core RBAC has been extended over temporal, spatial and spatiotemporal dimensions. The various models developed so far predominantly deal with monotonic policies which allow access only if there is a corresponding positive authorization. However, in many practical situations, there is a need for specifying policies that deny access through negative authorization. The authorization may again depend on different spatiotemporal conditions. In this paper, the notion of user-role-permission (URP) relation is used to incorporate negative authorization in ESTARBAC, one of the existing spatiotemporal RBAC models. The proposed method has been compared with two other existing approaches. We also analyze how negative authorization can facilitate expressing some of the important access control policies relevant for an organization.
Key concepts: Role-based access control, Authorization, Access control, Permission, Computer science, Computer access control, Computer security, Relevance (law)