Sciweavers

ESORICS
2006
Springer

Delegation in Role-Based Access Control

13 years 8 months ago
Delegation in Role-Based Access Control
User delegation is a mechanism for assigning access rights available to a user to another user. A delegation operation can either be a grant or transfer operation. Delegation for role-based access control models have extensively studied grant delegations. However, transfer delegations for role-based access control have largely been ignored. This is largely because enforcing transfer delegation policies is more complex than grant delegation policies. This paper, primarily, studies transfer delegations for role-based access control models. We also include grant delegations in our model for completeness. We present various mechanisms that authorise delegations in our model. In particular, we show that the use of administrative scope for authorising delegations is more efficient than using relations. We also discuss the enforcement and revocation of delegations. Finally, we compare our work with relevant work in the literature.
Jason Crampton, Hemanth Khambhammettu
Added 22 Aug 2010
Updated 22 Aug 2010
Type Conference
Year 2006
Where ESORICS
Authors Jason Crampton, Hemanth Khambhammettu
Comments (0)