Administrative Scope: A Foundation for Role-Based Administrative Models. / Crampton, J.; Loizou, G.

In: ACM Transactions on Information and System Security, Vol. 6, No. 2, 2003, p. 201-231.

Research output: Contribution to journalArticle

Published

Abstract

We introduce the concept of administrative scope in a role hierarchy and demonstrate that it can be used as a basis for role-based administration. We then develop a family of models for role hierarchy administration (RHA) employing administrative scope as the central concept. We then extend 4, the most complex model in the family, to a complete, decentralized model for role-based administration. We show that SARBAC, the resulting role-based administrative model, has significant practical and theoretical advantages over ARBAC97. We also discuss how administrative scope might be applied to the administration of general hierarchical structures, how our model can be used to reduce inheritance in the role hierarchy and how it can be configured to support discretionary access control features.
Original languageEnglish
Number of pages31
Pages201-231
JournalACM Transactions on Information and System Security
Journal publication date2003
Journal number2
Volume6
DOIs
StatePublished

ID: 1275370