The Experts below are selected from a list of 32754 Experts worldwide ranked by ideXlab platform
Bong-nam Noh - One of the best experts on this subject based on the ideXlab platform.
-
A framework for modeling organization structure in role engineering
Lecture Notes in Computer Science, 2006Co-Authors: Hyung-hyo Lee, Younglok Lee, Bong-nam NohAbstract:RBAC model is renowned as a Security model for corporate environment, since its components, especially role hierarchy, are suitable for modeling an organization structure. But the functional role hierarchy constructed through the existing role engineering approaches does not reflect an organization structure, because they do not take the structural characteristics of the organization into account. Also, it has been observed that the unconditional permission inheritance property in functional role hierarchy may breach a least privilege Security Principle and make it impossible to define separation of duty requirements on roles that have a common senior role. In this paper, we propose a role engineering methodology considering organizational roles as well as functional roles to provide a practical RBAC model for corporate environment. We also elaborate the characteristics of organizational roles relatively neglected in the previous work, and compare them with those of functional roles. And models for associating organizational and functional roles and those role hierarchies (unified vs. separate) are proposed and the advantages and shortcomings of those models are given.
-
PARA - A framework for modeling organization structure in role engineering
Applied Parallel Computing. State of the Art in Scientific Computing, 2004Co-Authors: Hyung-hyo Lee, Younglok Lee, Bong-nam NohAbstract:RBAC model is renowned as a Security model for corporate environment, since its components, especially role hierarchy, are suitable for modeling an organization structure. But the functional role hierarchy constructed through the existing role engineering approaches does not reflect an organization structure, because they do not take the structural characteristics of the organization into account. Also, it has been observed that the unconditional permission inheritance property in functional role hierarchy may breach a least privilege Security Principle and make it impossible to define separation of duty requirements on roles that have a common senior role. In this paper, we propose a role engineering methodology considering organizational roles as well as functional roles to provide a practical RBAC model for corporate environment. We also elaborate the characteristics of organizational roles relatively neglected in the previous work, and compare them with those of functional roles. And models for associating organizational and functional roles and those role hierarchies (unified vs. separate) are proposed and the advantages and shortcomings of those models are given.
Roelf J. Wieringa - One of the best experts on this subject based on the ideXlab platform.
-
Modelling mobility aspects of Security policies
Lecture Notes in Computer Science, 2005Co-Authors: Pieter H. Hartel, Pascal Van Eck, Sandro Etalle, Roelf J. WieringaAbstract:Security policies are rules that constrain the behaviour of a system. Different, largely unrelated sets of rules typically govern the physical and logical worlds. However, increased hardware and software mobility forces us to consider those rules in an integrated fashion. We present SPIN models of four case studies where mobility plays a role. At present our models are ad-hoc. In each case the model captures both the system of interest and its Security policy. The model is then formally checked against a Security Principle. The model checking activity shows examples of policies that are too weak to cope with mobility.
-
CASSIS - Modelling mobility aspects of Security policies
Construction and Analysis of Safe Secure and Interoperable Smart Devices, 2004Co-Authors: Pieter H. Hartel, Pascal Van Eck, Sandro Etalle, Roelf J. WieringaAbstract:Security policies are rules that constrain the behaviour of a system. Different, largely unrelated sets of rules typically govern the physical and logical worlds. However, increased hardware and software mobility forces us to consider those rules in an integrated fashion. We present SPIN models of four case studies where mobility plays a role. At present our models are ad-hoc. In each case the model captures both the system of interest and its Security policy. The model is then formally checked against a Security Principle. The model checking activity shows examples of policies that are too weak to cope with mobility.
Memon Asim - One of the best experts on this subject based on the ideXlab platform.
-
Separation of Duty in Role Based Access
2015Co-Authors: Francis M. Kugblenu, Memon AsimAbstract:In today’s business world, many organizations use Information Systems to many their sensitive and business critical information. The need to protect such a key component of the organization cannot be over emphasized. Access control has been found to be one of the effective ways of insuring that only authorized users have access to the information resources to perform their job function. Role Based Access Control has been found to be the access control mechanism that fits naturally with the organizational structure of businesses. Separation of duties is a Security Principle that has been used extensively to prevent conflict of interest, fraud and error control in organizations. In this thesis, we identify the various forms of separation of duties in role based access control systems. We also do a case study of the role based access control system in the banking application of a financial institution.
Nayef R F Alrodhan - One of the best experts on this subject based on the ideXlab platform.
-
the geopolitics of human enhancement applying the multi sum Security Principle
2011Co-Authors: Nayef R F AlrodhanAbstract:In my book, The Five Dimensions of Global Security: Proposal for a Multi-Sum Security Principle,1 I outline a new, multifaceted approach to global Security. It is my contention that global Security can no longer be considered merely a collection of different nations acting strictly on behalf of their own national Security interests. In the globalized world we live in, Security concerns have moved dramatically beyond national borders and must now be evaluated from all levels, starting with the individual and the nation state and working up to environmental, transnational and transcultural issues.
Eslam Nazemi - One of the best experts on this subject based on the ideXlab platform.
-
ICITST - A policy based access control model for web services
2011Co-Authors: Hadiseh Seyyed Alipour, Mehdi Sabbari, Eslam NazemiAbstract:Access control Security is one of the important aspects in Service Oriented Architecture (SOA) that is considered as a challenge. This issue requires further attention and review because of the architecture's distributed nature, its high re-usability, simple accessibility and the autonomy of logical solutions units. Since the most important way for implementing SOA is the use of web services, in this paper we propose an access control model for web services to protect services and to adopt some policies on the applications using SAML and XACML standard languages. This model is defined in terms of its authentication, authorization architecture and policy formulation. Separation of duties (SoD) is a Security Principle that has been used extensively to prevent conflict of interest, fraud and error control in organizations. In recent years many IT organizations have struggled to identify potential SoD violations within their IT systems. Hence we propose an approach to defining SoD policy rules in our model.