The <i>RSL99</i> language for role-based separation of duty constraints
Published 28 October 1999Open access
Gail‐Joon Ahn, Ravi Sandhu
Citations123
Generate an AI Snapshot to get a quick, structured summary of this paper.
Study Snapshot
ObjectiveStudy objective
MethodsResearch methodology
PopulationPopulation studied
Sample sizeSample sizes
OutcomesStudy outcomes here
ResultsStudy results comes here
LimitationsResearch study limitations comes here
A concise AI-generated summary of the paper will appear here once you click Generate AI Snapshot.
TL;DR
A framework for specifying separation of duty and conflict of interest policies in role-based systems is described and an intuitive formal language which uses system functions and sets as its basic elements is proposed.
Abstract
of duty (SOD) is a fundamental technique for prevention of fraud and errors, known and practiced long before the existence of computers.
Keywords
Social SciencesComputer Science
ComputerRole-based access control models
5,757 Citations1996Ravi Sandhu, Edward J. Coyne +2 more
Why RBAC is receiving renewed attention as a method of security administration and review is explained, a framework of four reference models developed to better understandRBAC is described, and the use of RBAC to manage itself is discussed.
A Comparison of Commercial and Military Computer Security Policies
1,133 Citations1987David D. Clark, David R. Wilson
It is argued that a lattice model is not sufficient to characterize integrity policies, and that distinct mechanisms are needed to Control disclosure and to provide integrity.
ComputerLattice-based access control models
707 Citations1993Ravi Sandhu
A balanced perspective on lattice-based access control models is provided and information flow policies, the military lattice,Access control models, the Bell-LaPadula model, the Biba model and duality, and the Chinese Wall lattice are reviewed.
ACM Transactions on Information and System SecurityA role-based access control model and reference implementation within a corporate intranet
440 Citations1999David F. Ferraiolo, John Barkley +1 more
NIST's enhanced RBAC model and the approach to designing and implementing RBAC features for networked Web servers are described, which provides administrators with a means of managing authorization data at the enterprise level, in a manner consistent with the current set of laws, regulations, and practices.
Separation of duty in role-based environments
351 Citations2002Richard T. Simon, Mary Ellen Zurko
The mechanisms to support separation of duty and roles in Adage, a general-purpose authorization language and toolkit are discussed and the notion of history-based separation ofduty is added.
ACM Transactions on Information and System SecurityThe role graph model and conflict of interest
278 Citations1999Matunda Nyanchama, Sylvia L. Osborn
This work describes in more detail the reference model for role-based access control introduced by Nyanchama and Osborn, and the role-graph model with its accompanying algorithms, which is one way of implementing role-role relationships.
On the formal definition of separation-of-duty policies and their composition
223 Citations2002Virgil D. Gligor, Serban I. Gavrila +1 more
It is concluded that the practical implementation of SoD policies requires new methods and tools for security administration, even within applications that already support RBAC, such as most database management systems.
Lecture notes in computer scienceRole hierarchies and constraints for lattice-based access controls
198 Citations1996Ravi Sandhu
This paper formally show that lattice-based mandatory access controls can be enforced by appropriate configuration of RBAC components and constructions demonstrate that role hierarchies and constraints are required to effectively achieve this result.
Transaction control expressions for separation of duties
165 Citations2003Ravi Sandhu
The author describes a model and notation for specifying and enforcing aspects of integrity policies, particularly separation of duties, to associate a transaction control expression with each information object.
Mutual exclusion of roles as a means of implementing separation of duty in role-based access control systems
156 Citations1997D. Richard Kuhn
This paper explores some aspects of mutual exclusion of roles as a means of implementing separation ofduty policies, including a safety property for separation of duty; relationships between different types of exclusion rules; properties of Mutual exclusion for roles; constraints on the role hierarchy introduced by mutual exclusion rules.
Rationale for the RBAC96 family of access control models
125 Citations1996Ravi Sandhu
The rationale for the major decisions in developing the RBAC96 models is given and alternatives that were considered are discussed.
Some conundrums concerning separation of duty
123 Citations1990Mike Nash, K.R. Poland
An examination is made of questions concerning commercial computer security integrity policies and it is shown that it implements a well-defined and sensible integrity policy that includes separation of duty, yet fails to meet either the TCSEC or the D.D.R. Wilson (1987) rules.
Naming and grouping privileges to simplify security management in large databases
111 Citations1990R W Baldwin
The main conclusion is that the naming and abstraction mechanism provided by NPDs can simplify security management in much the same way that procedures can simplify programming.
Conceptual foundations for a model of task-based authorizations
103 Citations2002Roshan K. Thomas, Ravi Sandhu
Constraints for role-based access control
92 Citations1996Chen Fang, Ravi Sandhu
This work is intended for classroom use only and must not be used for commercial advantage or used for profit or commercial advantage.
