In this paper we describe the formal specification language RASP for expressing fine-grained access control constraints in information systems. The design of the language is motivated by a number of IS case studies which demonstrate the complexity of the access constraints which arise if minimal (need-to-know) access is to be strictly enforced. RASP supports modularity, parameterization, role acquisition, constraint expressions and a symmetrical approach to role transitions and attribute transitions. No existing access control specification language supports all of these complex, realistic requirements.
Real Time Impact Factor:
1.66667
Author Name: Mark Evered
URL: View PDF
Keywords: Security, Access Control, Specification, Roles, Attributes
ISSN:
EISSN: 2305-0012
EOI/DOI:
Add Citation
Views: 1