A Critique of the ANSI Standard on Role-Based Access Control

A Critique of the ANSI Standard on Role-Based Access Control
复制标题

DOI:
10.1109/msp.2007.158
复制
发表时间:
2007-11
影响因子:
1.9
通讯作者:
Ninghui Li;Ji-Won Byun;E. Bertino
Ninghui Li;Ji-Won Byun;E. Bertino
中科院分区:
计算机科学4区
文献类型:
--
作者:
Ninghui Li;Ji-Won Byun;E. Bertino

文献摘要

被引文献

相似文献

In 2004, the American National Standards Institute approved the Role-Based Access Control standard to fulfill "a need among government and industry purchasers of information technology products for a consistent and uniform definition of role based access control (RBAC) features". Such uniform definitions give IT product vendors and customers a common and unambiguous terminology for RBAC features, which can lead to wider adoption of RBAC and increased productivity. However, the current ANSI RBAC Standard has several limitations, design flaws, and technical errors that, it unaddressed, could lead to confusions among IT product vendors and customers and to RBAC implementations with different semantics, thus defeating the standard's purpose.