Cargando…

Dynamic Authorization Specification for RBAC at CERN

Role-based access control (RBAC) project at CERN was designed to protect from accidental and unauthorized access to the LHC and injector equipment. Our model of RBAC introduces concept of dynamic authorization. Dynamic authorization is the authorization algorithm which takes into account not only de...

Descripción completa

Detalles Bibliográficos
Autor principal: Yastrebov, Ilia
Lenguaje:eng
Publicado: 2009
Materias:
Acceso en línea:http://cds.cern.ch/record/1227225
Descripción
Sumario:Role-based access control (RBAC) project at CERN was designed to protect from accidental and unauthorized access to the LHC and injector equipment. Our model of RBAC introduces concept of dynamic authorization. Dynamic authorization is the authorization algorithm which takes into account not only defined permissions, but also the internal state of each device server, called checking policy. This paper describes motivation of this algorithm and gives detailed explanation for each checking policy.