Skip to main content
Kent Academic Repository

Multi-Session Separation of Duties (MSoD) for RBAC

Chadwick, David W. and Xu, Wensheng and Otenko, Sassa and Laborde, Romain and Nasser, Bassem (2007) Multi-Session Separation of Duties (MSoD) for RBAC. In: 2007 IEEE 23rd International Conference on Data Engineering Workshop. IEEE, pp. 744-753. ISBN 978-1-4244-0831-3. (doi:10.1109/ICDEW.2007.4401062) (KAR id:14595)

Abstract

Separation of duties (SoD) is a key security requirement for many business and information systems. Role Based Access Controls (RBAC) is a relatively new paradigm for protecting information systems. In the ANSI standard RBAC model both static and dynamic SoD are defined. However, static SoD policies assume that the system has full control over the assignment of all roles to users, whilst dynamic SoD policies assume that conflicts of interest can only arise during the simultaneous activation of a user's roles. Unfortunately neither of these assumptions hold true in dynamic virtual organisations (VOs), or in business processes that span multiple user sessions, or where users only partially disclose their roles at each session. In this paper we propose multi-session SoD (MSoD) policies for business processes which include multiple tasks enacted by multiple users over many user access control sessions. We explore the means to define MSoD policies in RBAC via multi-session mutually exclusive roles (MMER) and multi-session mutually exclusive privileges (MMEP). We propose an approach to expressing MSoD policies in XML and enforcing MSoD policies in a policy controlled RBAC infrastructure. Finally, we describe how we have implemented MSoD policies in the PERMIS Privilege Management Infrastructure

Item Type: Book section
DOI/Identification number: 10.1109/ICDEW.2007.4401062
Uncontrolled keywords: RBAC, SoD, MSoD
Subjects: Q Science > QA Mathematics (inc Computing science) > QA 76 Software, computer programming,
Divisions: Divisions > Division of Computing, Engineering and Mathematical Sciences > School of Computing
Depositing User: Mark Wheadon
Date Deposited: 24 Nov 2008 18:05 UTC
Last Modified: 05 Nov 2024 09:49 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/14595 (The current URI for this page, for reference purposes)

University of Kent Author Information

  • Depositors only (login required):

Total unique views for this document in KAR since July 2020. For more details click on the image.