2009•Unpublished venueRequires access

Supporting Negative Authorization in Spatiotemporal Role Based Access Control

Samrat Mondal, Shamik Sural

Open publisher page 0 citations

Abstract

Role based access control (RBAC) has emerged as an effective solution for several access control problems of relevance today. To cope with the growing requirements, core RBAC has been extended over temporal, spatial and spatiotemporal dimensions. The various models developed so far predominantly deal with monotonic policies which allow access only if there is a corresponding positive authorization. However, in many practical situations, there is a need for specifying policies that deny access through negative authorization. The authorization may again depend on different spatiotemporal conditions. In this paper, the notion of user-role-permission (URP) relation is used to incorporate negative authorization in ESTARBAC, one of the existing spatiotemporal RBAC models. The proposed method has been compared with two other existing approaches. We also analyze how negative authorization can facilitate expressing some of the important access control policies relevant for an organization.

About this research paper

What this paper is about

Role based access control (RBAC) has emerged as an effective solution for several access control problems of relevance today. To cope with the growing requirements, core RBAC has been extended over temporal, spatial and spatiotemporal dimensions. The various models developed so far predominantly deal with monotonic policies which allow access only if there is a corresponding positive authorization. However, in many practical situations, there is a need for specifying policies that deny access through negative authorization. The authorization may again depend on different spatiotemporal conditions. In this paper, the notion of user-role-permission (URP) relation is used to incorporate negative authorization in ESTARBAC, one of the existing spatiotemporal RBAC models. The proposed method has been compared with two other existing approaches. We also analyze how negative authorization can facilitate expressing some of the important access control policies relevant for an organization.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Role based access control (RBAC) has emerged as an effective solution for several access control problems of relevance today. To cope with the growing requirements, core RBAC has been extended over temporal, spatial and spatiotemporal dimensions. The various models developed so far predominantly deal with monotonic policies which allow access only if there is a corresponding positive authorization. However, in many practical situations, there is a need for specifying policies that deny access through negative authorization. The authorization may again depend on different spatiotemporal conditions. In this paper, the notion of user-role-permission (URP) relation is used to incorporate negative authorization in ESTARBAC, one of the existing spatiotemporal RBAC models. The proposed method has been compared with two other existing approaches. We also analyze how negative authorization can facilitate expressing some of the important access control policies relevant for an organization.

Key concepts: Role-based access control, Authorization, Access control, Permission, Computer science, Computer access control, Computer security, Relevance (law)

Related papers

Back to paper searchBrowse research topicsOriginal source
Supporting Negative Authorization in Spatiotemporal Role Based Access Control — Research Paper | ScholarLens