Hierarchies in Contextual Role- Based Access Control Model (C-RBAC)
Muhammad Nabeel Tahir
Pages - 28 - 42     |    Revised - 15-8-2008     |    Published - 15-11-2008
Volume - 2   Issue - 4    |    Publication Date - August 2008  Table of Contents
Access Control, RBAC, Purpose Role, Spatial Role, Location Modeling.
Hierarchical representation is a natural way of organizing roles in role-based access control systems. Besides its advantages of providing a way of establishing parent-child relationships among different roles, it also provides a facility to design and organize context dependant application roles that users may activate depending on their current context (spatial, temporal) conditions. In this paper, we show that if spatial roles are organized in hierarchical relationships, it can cause the problem of disambiguation in making access control decisions especially when the user moves from one location to another location frequently in a single transaction and a single session. We extend our work of Contextual Role-Based Access Control (C-RBAC) by introducing hierarchical relationship among subject, location and purpose roles and solve the disambiguation problem in hierarchy by considering user motion direction and his/her context roles (spatial and spatial purpose) in order to make more fine grained and better access control decisions.
CITED BY (5)  
1 Grebenik, V. V., & Abraham, P. (2012). U.S. Patent No. 8,255,419. Washington, DC: U.S. Patent and Trademark Office.
2 W. Tang, M. Chen, J. Ni and X. Yang “Security Enhancement Mechanism Based on Contextual Authentication and Role Analysis for 2G-RFID Systems”. Sensors, 11(7), pp. 6743-6759. 2011.
3 W. Tang, J. Ni, M. Chen and X. Yang, “Contextual Role-Based Security Enhancement Mechanism for 2G-RFID Systems”, in Proceedings, Computer Communications Workshops (INFOCOM WKSHPS), IEEE Conference, Shanghai, 10-15 April 2011, pp. 942-946.
4 S. Gkarafli and A. A. Economides, “Comparing The Proof By Knowledge Authentication Techniques”, International Journal of Computer Science and Security (IJCSS), 4(2), pp. 237 – 255, 2010.
5 M. N. Tahir, “Purpose Engineering for Contextual Role-Based Access Control (C-RBAC)”, International Journal of Engineering (IJE), 2(3), pp. 41 – 50, 2008.
Mr. Muhammad Nabeel Tahir
- Malaysia