

Safeness Discussions on TRBAC and GTRBAC Model and an Improved Temporal Role-Based Access Control Model




Bertino et al. propose a temporal Role-based Access Control (TRBAC) model, and Joshi et al. propose a Generalized TRBAC (GTRBAC) model based on TRBAC. Some periodic constraints and duration constraints are introduced to express the corresponding time-based access control policy semantics and enhance the expressiveness of the temporal RBAC model. We have analyzed the TRBAC and GTRBAC models and pointed out that the sufficient conditions for guaranteeing the safeness of the GTRBAC model was not comprehensive, so we have analyzed the reasons and designed a process rule to solve the safety problem. In this paper, an improved process rule is designed to solve the safety problem. In addition, a fault about translating a dependent trigger of TRBAC into an Oracle trigger is analyzed. In order to ensure the temporal RBAC model better, an Improved Generalized Temporal Role-based Access Control (IGTRBAC) based on the TRBAC and GTRBAC models is put forward. The two proposed restrictions in the IGTRBAC model are used to resolve the security problems caused by the dependent trigger and the cardinality constraint on role activation. At last, case study shows that the IGTRBAC model is safe.


 1. Introduction
 2. Preliminaries
  2.1. RBAC Model
  2.2. Periodic Expression
 3. Discussion on Sufficient Safeness Condition for TRBAC and GTRBAC Model
 4. Discussion on TRBAC Trigger Translation Algorithm
 5. IGTRBAC Model
 6. Conclusions


  • Meng Liu Computer Application Research Center, Shenzhen Graduate School, Harbin Institute of Technology, Shenzhen 518055, China, School of Mechanical, Electrical and Information Engineering, Shandong University, Weihai 264209, China
  • Xuan Wang Computer Application Research Center, Shenzhen Graduate School, Harbin Institute of Technology, Shenzhen 518055, China, Public Service Platform of Mobile Internet Application Security Industry, Shenzhen 518055, China, Shenzhen Applied Technology Engineering Laboratory for Internet Multimedia Application, Shenzhen 518055, China


자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.