|
|
A Formal Approach for Risk Assessment in RBAC Systems
|
|
|
|
|
نویسنده
|
Ma Ji
|
منبع
|
journal of universal computer science - 2012 - دوره : 18 - شماره : 17 - صفحه:2432 -2451
|
چکیده
|
Risk assessment and access control are important issues in cloud computing.in this paper, we propose a formal approach to risk assessment for rbac systems, in which access control decisions are taken after consideration of risk assessment. the risk assessment method considers partial orderings on objects and actions, which allow us to effectively capture the notions of importance of objects and criticality of actions and then to determine the risk of assigning a specific role to a specific user. we in particular consider the cases of permission assignment and delegation assignment.
|
کلیدواژه
|
Risk assessment ,access control ,RBAC ,poset ,security classification
|
آدرس
|
Christian Doppler Laboratory for Client-Centric Cloud Computing, Austria
|
پست الکترونیکی
|
j.ma@cdcc.faw.jku.at
|
|
|
|
|
|
|
|
|
|
|
|
Authors
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|