• 0
    • ارسال درخواست
    • حذف همه
    • Industrial Standards
    • Defence Standards
  • درباره ما
  • درخواست موردی
  • فهرست استانداردها
    • Industrial Standards
    • Defence Standards
  • راهنما
  • Login
  • لیست خرید شما 0
    • ارسال درخواست
    • حذف همه
View Item 
  •   YSE
  • Industrial Standards
  • ANSI - American National Standards Institute
  • View Item
  •   YSE
  • Industrial Standards
  • ANSI - American National Standards Institute
  • View Item
  • All Fields
  • Title(or Doc Num)
  • Organization
  • Year
  • Subject
Advanced Search
JavaScript is disabled for your browser. Some features of this site may not work without it.

Archive

ANSI INCITS 494

Information Technology – Role Based Access Control – Policy-Enhanced

Organization:
ANSI - American National Standards Institute
Year: 2012

Abstract: Role Based Access Control (RBAC) has been criticized for the difficulty of setting up an initial role structure and for inflexibility in rapidly changing domains. A pure RBAC solution may provide inadequate support for dynamic attributes, such as time of day, which might need to be considered when determining user permissions. This RBAC Policy-Enhanced standard (to be referenced as RPE) provides a framework and functional specifications to handle the relationship between roles and dynamic constraints. Some of the administrative and user permission review advantages of RBAC are retained while allowing the access control system to work in a rapidly changing environment.
The RPE defines the scope and context for role-role, user-role, and attribute-sensitive dynamic constraints which can be implemented in a run-time environment. This standard defines the functional areas of External Policy Interfaces, the RBAC Engine, and enhanced dynamic constraint mechanisms of the RBAC Policy-Enhanced Reference Model. Additional interfaces have been included to provide visibility into the system for integrity checking (RBAC Implementation and Interoperability Interface) and Audit Monitoring of the RPE access control model. These RPE features extend the dynamic constraints of RBAC (INCITS 359-2012), which primarily emphasize Separation of Duty (SoD) functions.
The RPE allows external policies (rules and data) to implement constraints on the core role components within the base RBAC Reference Model (INCITS 359-2012) and define dynamic constraints which may be applied to users, roles, operations, objects, and permissions. These enhancements are defined through several mechanisms including an RBAC Engine algorithm, supporting system functions for the RBAC Engine, an external security policy interface and the definitions of dynamic constraint primitives and operations. These combined features enable the RPE to define and implement the least privilege conditions (fine-grained authorization) necessary to tailor the base RBAC Reference Model to various attributes and dynamic constraints.
Extending the static constraints of RBAC (INCITS 359-2012), the RPE also defines static constraints, which consist of role-role, permission-permission, permission-role, and user-role constraints. Static constraints are constraints that take effect prior to run time and are enforced by administrative processes.
Informative Annex A provides references for this document. Informative Annex B presents the table of RBAC Implementation and Interoperability Standard (RIIS) Management Functions, which are commands for reviewing the status of the RBAC Engine described in this work.
URI: http://mapnamagz.yabesh.ir/std;query=authoF23793FD08/handle/yse/69990
Collections :
  • ANSI - American National Standards Institute
  • Download PDF : (452.1Kb)
  • Show Full MetaData Hide Full MetaData
  • Statistics

    ANSI INCITS 494

Show full item record

contributor authorANSI - American National Standards Institute
date accessioned2017-09-04T16:06:47Z
date available2017-09-04T16:06:47Z
date copyright2012.07.26
date issued2012
identifier otherBHYBYEAAAAAAAAAA.pdf
identifier urihttp://mapnamagz.yabesh.ir/std;query=authoF23793FD08/handle/yse/69990
description abstractRole Based Access Control (RBAC) has been criticized for the difficulty of setting up an initial role structure and for inflexibility in rapidly changing domains. A pure RBAC solution may provide inadequate support for dynamic attributes, such as time of day, which might need to be considered when determining user permissions. This RBAC Policy-Enhanced standard (to be referenced as RPE) provides a framework and functional specifications to handle the relationship between roles and dynamic constraints. Some of the administrative and user permission review advantages of RBAC are retained while allowing the access control system to work in a rapidly changing environment.
The RPE defines the scope and context for role-role, user-role, and attribute-sensitive dynamic constraints which can be implemented in a run-time environment. This standard defines the functional areas of External Policy Interfaces, the RBAC Engine, and enhanced dynamic constraint mechanisms of the RBAC Policy-Enhanced Reference Model. Additional interfaces have been included to provide visibility into the system for integrity checking (RBAC Implementation and Interoperability Interface) and Audit Monitoring of the RPE access control model. These RPE features extend the dynamic constraints of RBAC (INCITS 359-2012), which primarily emphasize Separation of Duty (SoD) functions.
The RPE allows external policies (rules and data) to implement constraints on the core role components within the base RBAC Reference Model (INCITS 359-2012) and define dynamic constraints which may be applied to users, roles, operations, objects, and permissions. These enhancements are defined through several mechanisms including an RBAC Engine algorithm, supporting system functions for the RBAC Engine, an external security policy interface and the definitions of dynamic constraint primitives and operations. These combined features enable the RPE to define and implement the least privilege conditions (fine-grained authorization) necessary to tailor the base RBAC Reference Model to various attributes and dynamic constraints.
Extending the static constraints of RBAC (INCITS 359-2012), the RPE also defines static constraints, which consist of role-role, permission-permission, permission-role, and user-role constraints. Static constraints are constraints that take effect prior to run time and are enforced by administrative processes.
Informative Annex A provides references for this document. Informative Annex B presents the table of RBAC Implementation and Interoperability Standard (RIIS) Management Functions, which are commands for reviewing the status of the RBAC Engine described in this work.
languageEnglish
titleANSI INCITS 494num
titleInformation Technology – Role Based Access Control – Policy-Enhanceden
typestandard
page27
statusActive
treeANSI - American National Standards Institute:;2012
contenttypefulltext
DSpace software copyright © 2017-2020  DuraSpace
نرم افزار کتابخانه دیجیتال "دی اسپیس" فارسی شده توسط یابش برای کتابخانه های ایرانی | تماس با یابش
yabeshDSpacePersian
 
DSpace software copyright © 2017-2020  DuraSpace
نرم افزار کتابخانه دیجیتال "دی اسپیس" فارسی شده توسط یابش برای کتابخانه های ایرانی | تماس با یابش
yabeshDSpacePersian