A Study of Usage Control Model in Role-Based Access Control System

碩士 === 中原大學 === 資訊工程研究所 === 93 === In traditional RBAC systems, a user’s access rights will be checked and authorized before system resources can be used. But this is not enough in some situations, so that the concepts of usage control were introduced. Usage control allows three kinds of authorizati...

Full description

Bibliographic Details
Main Authors: Tseng-Wei Chan, 曾瑋展
Other Authors: Chung-Shyan Liu
Format: Others
Language:zh-TW
Published: 2005
Online Access:http://ndltd.ncl.edu.tw/handle/sc2rd9
id ndltd-TW-093CYCU5392008
record_format oai_dc
spelling ndltd-TW-093CYCU53920082019-05-15T20:05:51Z http://ndltd.ncl.edu.tw/handle/sc2rd9 A Study of Usage Control Model in Role-Based Access Control System 以角色為主之權限控管系統中使用控制模組之研究與實作 Tseng-Wei Chan 曾瑋展 碩士 中原大學 資訊工程研究所 93 In traditional RBAC systems, a user’s access rights will be checked and authorized before system resources can be used. But this is not enough in some situations, so that the concepts of usage control were introduced. Usage control allows three kinds of authorization decisions: authorization, obligation and condition. Obligation means that a user needs to do some things to get access rights, and conditions may be used to restrict a user’s access rights. There are also mutable property and continuity property in usage control. Thus, the roles that a user can use can be decided at runtime. For example, in an on-line service system, a user must have more cash in order to obtain the read service. Like reading a book, and system will ask the user to pay more in order to continue reading when the access rights expire. In this thesis, we studied on how to integrate usage control model into a role-based access control system, and implemented a system for checking user’s rights at runtime. The implementation includes (1) an administrator's interface to help the administrator to manage users and their attributes, (2) attributes update that allows pre-update, ongoing-update and post-update of user’s attributes, and (3) dynamic separation of duty to check the values of user’s attributes to prevent a user from holding exclusive roles at the same time. Chung-Shyan Liu 留忠賢 2005 學位論文 ; thesis 51 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 中原大學 === 資訊工程研究所 === 93 === In traditional RBAC systems, a user’s access rights will be checked and authorized before system resources can be used. But this is not enough in some situations, so that the concepts of usage control were introduced. Usage control allows three kinds of authorization decisions: authorization, obligation and condition. Obligation means that a user needs to do some things to get access rights, and conditions may be used to restrict a user’s access rights. There are also mutable property and continuity property in usage control. Thus, the roles that a user can use can be decided at runtime. For example, in an on-line service system, a user must have more cash in order to obtain the read service. Like reading a book, and system will ask the user to pay more in order to continue reading when the access rights expire. In this thesis, we studied on how to integrate usage control model into a role-based access control system, and implemented a system for checking user’s rights at runtime. The implementation includes (1) an administrator's interface to help the administrator to manage users and their attributes, (2) attributes update that allows pre-update, ongoing-update and post-update of user’s attributes, and (3) dynamic separation of duty to check the values of user’s attributes to prevent a user from holding exclusive roles at the same time.
author2 Chung-Shyan Liu
author_facet Chung-Shyan Liu
Tseng-Wei Chan
曾瑋展
author Tseng-Wei Chan
曾瑋展
spellingShingle Tseng-Wei Chan
曾瑋展
A Study of Usage Control Model in Role-Based Access Control System
author_sort Tseng-Wei Chan
title A Study of Usage Control Model in Role-Based Access Control System
title_short A Study of Usage Control Model in Role-Based Access Control System
title_full A Study of Usage Control Model in Role-Based Access Control System
title_fullStr A Study of Usage Control Model in Role-Based Access Control System
title_full_unstemmed A Study of Usage Control Model in Role-Based Access Control System
title_sort study of usage control model in role-based access control system
publishDate 2005
url http://ndltd.ncl.edu.tw/handle/sc2rd9
work_keys_str_mv AT tsengweichan astudyofusagecontrolmodelinrolebasedaccesscontrolsystem
AT céngwěizhǎn astudyofusagecontrolmodelinrolebasedaccesscontrolsystem
AT tsengweichan yǐjiǎosèwèizhǔzhīquánxiànkòngguǎnxìtǒngzhōngshǐyòngkòngzhìmózǔzhīyánjiūyǔshízuò
AT céngwěizhǎn yǐjiǎosèwèizhǔzhīquánxiànkòngguǎnxìtǒngzhōngshǐyòngkòngzhìmózǔzhīyánjiūyǔshízuò
AT tsengweichan studyofusagecontrolmodelinrolebasedaccesscontrolsystem
AT céngwěizhǎn studyofusagecontrolmodelinrolebasedaccesscontrolsystem
_version_ 1719096146339561472