A Study of Usage Control Model in Role-Based Access Control System
碩士 === 中原大學 === 資訊工程研究所 === 93 === In traditional RBAC systems, a user’s access rights will be checked and authorized before system resources can be used. But this is not enough in some situations, so that the concepts of usage control were introduced. Usage control allows three kinds of authorizati...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2005
|
Online Access: | http://ndltd.ncl.edu.tw/handle/sc2rd9 |
id |
ndltd-TW-093CYCU5392008 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-093CYCU53920082019-05-15T20:05:51Z http://ndltd.ncl.edu.tw/handle/sc2rd9 A Study of Usage Control Model in Role-Based Access Control System 以角色為主之權限控管系統中使用控制模組之研究與實作 Tseng-Wei Chan 曾瑋展 碩士 中原大學 資訊工程研究所 93 In traditional RBAC systems, a user’s access rights will be checked and authorized before system resources can be used. But this is not enough in some situations, so that the concepts of usage control were introduced. Usage control allows three kinds of authorization decisions: authorization, obligation and condition. Obligation means that a user needs to do some things to get access rights, and conditions may be used to restrict a user’s access rights. There are also mutable property and continuity property in usage control. Thus, the roles that a user can use can be decided at runtime. For example, in an on-line service system, a user must have more cash in order to obtain the read service. Like reading a book, and system will ask the user to pay more in order to continue reading when the access rights expire. In this thesis, we studied on how to integrate usage control model into a role-based access control system, and implemented a system for checking user’s rights at runtime. The implementation includes (1) an administrator's interface to help the administrator to manage users and their attributes, (2) attributes update that allows pre-update, ongoing-update and post-update of user’s attributes, and (3) dynamic separation of duty to check the values of user’s attributes to prevent a user from holding exclusive roles at the same time. Chung-Shyan Liu 留忠賢 2005 學位論文 ; thesis 51 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 中原大學 === 資訊工程研究所 === 93 === In traditional RBAC systems, a user’s access rights will be checked and authorized before system resources can be used. But this is not enough in some situations, so that the concepts of usage control were introduced. Usage control allows three kinds of authorization decisions: authorization, obligation and condition. Obligation means that a user needs to do some things to get access rights, and conditions may be used to restrict a user’s access rights. There are also mutable property and continuity property in usage control. Thus, the roles that a user can use can be decided at runtime. For example, in an on-line service system, a user must have more cash in order to obtain the read service. Like reading a book, and system will ask the user to pay more in order to continue reading when the access rights expire.
In this thesis, we studied on how to integrate usage control model into a role-based access control system, and implemented a system for checking user’s rights at runtime. The implementation includes (1) an administrator's interface to help the administrator to manage users and their attributes, (2) attributes update that allows pre-update, ongoing-update and post-update of user’s attributes, and (3) dynamic separation of duty to check the values of user’s attributes to prevent a user from holding exclusive roles at the same time.
|
author2 |
Chung-Shyan Liu |
author_facet |
Chung-Shyan Liu Tseng-Wei Chan 曾瑋展 |
author |
Tseng-Wei Chan 曾瑋展 |
spellingShingle |
Tseng-Wei Chan 曾瑋展 A Study of Usage Control Model in Role-Based Access Control System |
author_sort |
Tseng-Wei Chan |
title |
A Study of Usage Control Model in Role-Based Access Control System |
title_short |
A Study of Usage Control Model in Role-Based Access Control System |
title_full |
A Study of Usage Control Model in Role-Based Access Control System |
title_fullStr |
A Study of Usage Control Model in Role-Based Access Control System |
title_full_unstemmed |
A Study of Usage Control Model in Role-Based Access Control System |
title_sort |
study of usage control model in role-based access control system |
publishDate |
2005 |
url |
http://ndltd.ncl.edu.tw/handle/sc2rd9 |
work_keys_str_mv |
AT tsengweichan astudyofusagecontrolmodelinrolebasedaccesscontrolsystem AT céngwěizhǎn astudyofusagecontrolmodelinrolebasedaccesscontrolsystem AT tsengweichan yǐjiǎosèwèizhǔzhīquánxiànkòngguǎnxìtǒngzhōngshǐyòngkòngzhìmózǔzhīyánjiūyǔshízuò AT céngwěizhǎn yǐjiǎosèwèizhǔzhīquánxiànkòngguǎnxìtǒngzhōngshǐyòngkòngzhìmózǔzhīyánjiūyǔshízuò AT tsengweichan studyofusagecontrolmodelinrolebasedaccesscontrolsystem AT céngwěizhǎn studyofusagecontrolmodelinrolebasedaccesscontrolsystem |
_version_ |
1719096146339561472 |