Task-role-based access control model(T-RBAC) does not take the context of the subject and the object as a key factor in making access control and considers only a part of context information such as task order and the mutually exclusive tasks.This paper presents a dynamic context-sensitive access control model that extends T-RBAC while retaining its advantages of role hierarchy and task level access control.Since the context has been introduced and associated with the subject and the task in the extended model
it supports the dynamic transition of user’s roles and activates the access permissions needed to execute a task when considering the context of the subject and the object.According to the logic requirements of business process
this model builds a workflow context to support the static separation of duty(SoD) at permission level and the dynamic SoD at task instance level.It also uses passive session and active session approach to handle passive tasks and active tasks to support dynamic access control effectively.
关键词
访问控制上下文相关信息安全会话控制
Keywords
access controlcontext-sensitiveinformation securitysession control