Skip to primary content
ConsortiumInfo.org
Search
Sponsored by Gesmer Updegrove
  • Blog
  • About
  • Guide
  • SSO List
  • Meta Library
  • Journal
meta library

ABSTRACT: A Critique of the ANSI Standard on Role Based Access Control

Title
ABSTRACT: A Critique of the ANSI Standard on Role Based Access Control
Author
Ninghui Li, CERIAS and Department of Computer Science Purdue University, Ji-Won Byun, CERIAS and Department of Computer Science Purdue University, and Elisa Bertino, CERIAS and Department of Computer Science Purdue University
Date
6/20/2008
(Original Publish Date: 4/21/2005)
Abstract
The American National Standard Institute (ANSI) Standard on Role-Based Access Control (RBAC) was approved in 2004 to fulfil “a need among government and industry purchasers of information technology products for a consistent and uniform definition of role based access control (RBAC) features” [1]. The development of the ANSI RBAC standard represents an important milestone and will enhance portability and interoperability of applications and access control policies. The current version of the standard, however, has limitations, design flaws, and technical errors. In this article, we identify critical design problems in the current ANSI RBAC standard and suggest how they can be addressed. We also analyze several critical features of RBAC, such as sessions, hierarchies, and constraints, and discuss how they should be supported in RBAC models. We believe that our analysis will contribute to improvements in the RBAC standard and, more broadly, in the understanding of RBAC.
Link
Full Text (PDF)
Technical Areas
  • Best Practices
  • By Technical Area
  • Case Studies
  • Economics
  • Formation and Management
  • General/Other
  • General/Other
  • General/Other
  • Government
  • Information Technology
  • Markets
  • Participation
  • Participation (by Agencies)
  • Perspectives & Viewpoints
  • Process of Standard Setting
  • Procurement
  • Strategy
  • Systems Management
  • Technical Process
  • Technical Process
  • Value Proposition
Gesmer Updegrove
  • Terms of Use and Privacy Policy
  • Contact
  • Sitemap