Full Text Available

This is an Open Access publication published under CSC-OpenAccess Policy.
Separation of Duty and Context Constraints for Contextual Role-Based Access Control (C-RBAC)
Muhammad Nabeel Tahir
Pages - 16 - 26     |    Revised - 20-02-2009     |    Published - 15-03-2009
Volume - 3   Issue - 1    |    Publication Date - February 2009  Table of Contents
Separation of duty, Constraints, C-RBAC, Location Hierarchy Schemas.
This paper presents the separation of duty and context constraints of recently proposed Contextual Role-Based Access Control Model C-RBAC. Constraints in C-RBAC enabled the specification of a rich set of Separation of Duty (SoD) constraints over spatial purpose roles. In healthcare environment in which user roles are position and are purpose dependant, the notion of SoD is still meaningful and relevant to the concept of conflict of interest. SoD may be defined as Static Separation of Duty (SSoD) and Dynamic Separation of Duty (DSoD) depending on whether exclusive role constraints are evaluated against the user-role assignment set or against the set of roles activated in user’s session. In particular, the model is capable of expressing a wider range of constraints on spatial domains, location hierarchy schemas, location hierarchy instances, spatial purposes and spatial purpose roles.
Mr. Muhammad Nabeel Tahir
- Malaysia