A major development in the field of access control is the dominant role-based access control (RBAC) scheme. The fascination of RBAC lies in its enhanced security along with the concept of roles. In addition, attribute-based access control (ABAC) is added to the access control models, which is famous for its dynamic behavior. Separation of duty (SOD) is used for enforcing least privilege concept in RBAC and ABAC. Moreover, SOD is a powerful tool that is used to protect an organization from internal security attacks and threats. Di_erent problems have been found in the implementation of SOD at the role level. This paper discusses that the implementation of SOD on the level of roles is not a good option. Therefore, this paper proposes a hybrid access control model to implement SOD on the basis of permissions. The first part of the proposed model is based on the addition of attributes with dynamic characteristics in the RBAC model, whereas the second part of the model implements the permission-based SOD in dynamic RBAC model. Moreover, in comparison with previous models, performance and feature analysis are performed to show the strength of dynamic RBAC model. This model improves the performance of the RBAC model in terms of time, dynamicity, and automatic permissions and roles assignment. At the same time, this model also reduces the administrator’s load and provides a flexible, dynamic, and secure access control model.


    Access

    Download


    Export, share and cite



    Title :

    Permission-based separation of duty in dynamic role-based access control model



    Publication date :

    2019-01-01


    Remarks:

    Symmetry. - 11, 5 (2019) , 669, ISSN: 2073-8994



    Type of media :

    Article (Journal)


    Type of material :

    Electronic Resource


    Language :

    English



    Classification :

    DDC:    000 / 629



    Blockchain for Attribute-Based Access Control : A flexible access control scheme with Permission Delegations

    Vigmostad, Victor Larsen / Lauen, Torbjørn Thorvaldsen | BASE | 2021

    Free access

    BMS permission control method and permission control system based on check code

    GU JUNJIE / WANG JUN / WANG RUIHENG et al. | European Patent Office | 2023

    Free access

    Control method and control device for elevator access permission based on target detection

    XIONG AIMIN / LIU RENBO / YANG HAIBIN et al. | European Patent Office | 2022

    Free access

    Method and apparatus for dynamic vehicle access permission analysis and processing

    DIAMOND BRUCE F / WESTON KEITH / MCNEES MARK ANTHONY et al. | European Patent Office | 2023

    Free access