Designing Authorization Rules to Achieve Separation of Duty in Task-based Access Control Models

碩士 === 國立交通大學 === 資訊管理所 === 87 === Mutual-exclusive roles are the basis for designing authorization rules to achieve separation of duty in role-based access control (RBAC) models. However, in order to adapt to the changing business environments, enterprises need to operate with effective task manage...

Full description

Bibliographic Details
Main Authors: Mei-Yu Wu, 吳美玉
Other Authors: Duen-Ren Liu
Format: Others
Language:zh-TW
Published: 1999
Online Access:http://ndltd.ncl.edu.tw/handle/42544407434387096894
id ndltd-TW-087NCTU0396002
record_format oai_dc
spelling ndltd-TW-087NCTU03960022016-07-11T04:13:35Z http://ndltd.ncl.edu.tw/handle/42544407434387096894 Designing Authorization Rules to Achieve Separation of Duty in Task-based Access Control Models 設計授權準則以達到在工作為基礎的存取控制模式中之權責區分 Mei-Yu Wu 吳美玉 碩士 國立交通大學 資訊管理所 87 Mutual-exclusive roles are the basis for designing authorization rules to achieve separation of duty in role-based access control (RBAC) models. However, in order to adapt to the changing business environments, enterprises need to operate with effective task management as well as task-based access control. Current RBAC models are not adequate to provide effective management of tasks within enterprises. Although some works have been done in the context of role and task-based access control, very few works have designed authorization rules on separation of duty in this context. The designed authorization rules are merely simple extensions from the authorization rules of RBAC models. Moreover, different duty-relationships among tasks are not considered. This work presents a novel view to analyze different duty-relationships among tasks from the aspect of how enterprises design and plan tasks. Several kinds of duty-conflict tasks are defined to represent various duty-relationships such as balancing, supervising and non-arbitrary relationships among tasks. On the basis of the defined duty-conflict tasks, authorization rules for assigning tasks to roles and users are designed to achieve separation of duty. The proposed work not only defines new duty-conflict tasks but also deduces new authorization rules to achieve variations of separation of duty including supervision-based, work-dependent and coordination-based separation of duty, etc. Duen-Ren Liu Jing-Jang Hwang 劉敦仁 黃景彰 1999 學位論文 ; thesis 69 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 國立交通大學 === 資訊管理所 === 87 === Mutual-exclusive roles are the basis for designing authorization rules to achieve separation of duty in role-based access control (RBAC) models. However, in order to adapt to the changing business environments, enterprises need to operate with effective task management as well as task-based access control. Current RBAC models are not adequate to provide effective management of tasks within enterprises. Although some works have been done in the context of role and task-based access control, very few works have designed authorization rules on separation of duty in this context. The designed authorization rules are merely simple extensions from the authorization rules of RBAC models. Moreover, different duty-relationships among tasks are not considered. This work presents a novel view to analyze different duty-relationships among tasks from the aspect of how enterprises design and plan tasks. Several kinds of duty-conflict tasks are defined to represent various duty-relationships such as balancing, supervising and non-arbitrary relationships among tasks. On the basis of the defined duty-conflict tasks, authorization rules for assigning tasks to roles and users are designed to achieve separation of duty. The proposed work not only defines new duty-conflict tasks but also deduces new authorization rules to achieve variations of separation of duty including supervision-based, work-dependent and coordination-based separation of duty, etc.
author2 Duen-Ren Liu
author_facet Duen-Ren Liu
Mei-Yu Wu
吳美玉
author Mei-Yu Wu
吳美玉
spellingShingle Mei-Yu Wu
吳美玉
Designing Authorization Rules to Achieve Separation of Duty in Task-based Access Control Models
author_sort Mei-Yu Wu
title Designing Authorization Rules to Achieve Separation of Duty in Task-based Access Control Models
title_short Designing Authorization Rules to Achieve Separation of Duty in Task-based Access Control Models
title_full Designing Authorization Rules to Achieve Separation of Duty in Task-based Access Control Models
title_fullStr Designing Authorization Rules to Achieve Separation of Duty in Task-based Access Control Models
title_full_unstemmed Designing Authorization Rules to Achieve Separation of Duty in Task-based Access Control Models
title_sort designing authorization rules to achieve separation of duty in task-based access control models
publishDate 1999
url http://ndltd.ncl.edu.tw/handle/42544407434387096894
work_keys_str_mv AT meiyuwu designingauthorizationrulestoachieveseparationofdutyintaskbasedaccesscontrolmodels
AT wúměiyù designingauthorizationrulestoachieveseparationofdutyintaskbasedaccesscontrolmodels
AT meiyuwu shèjìshòuquánzhǔnzéyǐdádàozàigōngzuòwèijīchǔdecúnqǔkòngzhìmóshìzhōngzhīquánzéqūfēn
AT wúměiyù shèjìshòuquánzhǔnzéyǐdádàozàigōngzuòwèijīchǔdecúnqǔkòngzhìmóshìzhōngzhīquánzéqūfēn
_version_ 1718343449461129216