Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1145/1992896.1992897acmconferencesArticle/Chapter ViewAbstractPublication PagesuccsConference Proceedingsconference-collections
research-article

Mixing privacy with role-based access control

Published: 16 May 2011 Publication History

Abstract

In this paper we investigate different alternatives for including privacy purposes into role-based access control. We emphasize that not all permissions have a purpose, only those which deal with the use of data about individuals stored in a system need to have privacy labels. We develop a model for including privacy purposes in the Role Graph Model, and show its implementation in a prototype.

References

[1]
American National Standards Institute, Inc. Role-Based Access Control. ANSI INCITS 359-2004. Approved Feb. 3, 2004.
[2]
J.-W. Byun and N. Li. Purpose based access control for privacy protection in relational database systems. VLDB J., 17(4):603--619, 2008.
[3]
D. Ferraiolo and R. Kuhn. Role-based access control. In Proceedings of the NIST-NSA National Computer Security Conference, pages 554--563, 1992.
[4]
D. Ferraiolo, R. Sandhu, S. Gavrila, D. Kuhn, and R. Ch andramouli. Proposed NIST standard for role-based access control. ACM TISSEC, 4(3):224--275, 2001.
[5]
C. Ionita and S. Osborn. Privilege administration for the role graph model. In 16th IFIP WG11.3 Working Conference on Database & Application Security, pages 15--25. Kluwer Academic Publishers, 2002.
[6]
Q. Ni, A. Trombetta, E. Bertino, and J. Lobo. Privacy-aware role based access control. In SACMAT '07: Proceedings of the 12th ACM symposium on Access control models and technologies, pages 41--50, New York, NY, USA, 2007. ACM.
[7]
M. Nyanchama and S. Osborn. Access rights administration in role-based security systems. In Database Security, VIII Status and Prospects, pages 37--56. North Holland, 1994.
[8]
M. Nyanchama and S. Osborn. The role graph model and conflict of interest. ACM Trans. Information and Systems Security, 2(1):3--33, 1999.
[9]
S. L. Osborn. Role-based access control. In M. Petkovic and W. Jonker, editors, Security, Privacy and Trust in Modern Data Management, pages 55--70. Springer, 2007.
[10]
R. S. Sandhu, E. J. Coyne, H. L. Feinstein, and C. E. Youman. Role-based access control models. IEEE Computer, 29(2):38--47, 1996.
[11]
C. E. Shyni and S. Swamynathan. Purpose based access control for privacy protection in objectrelational database systems. In 2010 International Conference on Data Storage and Data Engineering, pages 90--94, 2010.
[12]
H. Wang and S. L. Osborn. Static and dynamic delegation in the role graph model. to appear, IEEE Trans. on Knowledge and Data Management, 2010.

Cited By

View all

Recommendations

Comments

Information & Contributors

Information

Published In

cover image ACM Conferences
C3S2E '11: Proceedings of The Fourth International C* Conference on Computer Science and Software Engineering
May 2011
162 pages
ISBN:9781450306263
DOI:10.1145/1992896
  • General Chair:
  • Bipin C. Desai,
  • Program Chairs:
  • Alain Abran,
  • Sudhir P. Mudur
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

Sponsors

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 16 May 2011

Permissions

Request permissions for this article.

Check for updates

Author Tags

  1. privacy
  2. privacy purpose hierarchy
  3. role-based access control

Qualifiers

  • Research-article

Conference

C3S2E '11
Sponsor:
  • ACM
  • Concordia University

Acceptance Rates

Overall Acceptance Rate 12 of 42 submissions, 29%

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)3
  • Downloads (Last 6 weeks)1
Reflects downloads up to 26 Sep 2024

Other Metrics

Citations

Cited By

View all

View Options

Get Access

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

Media

Figures

Other

Tables

Share

Share

Share this Publication link

Share on social media