Skip to main navigation Skip to search Skip to main content

Specification of Role and Attribute Transitions for Secure Information System Access

Mark P Evered

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Citation (Scopus)

Abstract

In this paper, we describe a formal specification language (RASP) for expressing fine-grained access control constraints in information systems. The design of the language is motivated by two HIS case studies which demonstrate the complexity of the access constraints which arise if minimal (need-to-know) access is to be strictly enforced. RASP supports modularity, parameterization, role acquisition, constraint expressions and a symmetrical approach to role transitions and attribute transitions. No existing access control specification language supports all of these complex, realistic requirements.
Original languageEnglish
Title of host publicationProceedings of the Second International Conference on Digital Information and Communication Technology and it's Applications (DICTAP)
Place of PublicationLos Alamitos, United States of America
PublisherInstitute of Electrical and Electronics Engineers (IEEE)
Pages230-235
ISBN (Print)9781467307321, 9781467307345, 9781467307338
DOIs
Publication statusPublished - 2012
EventDICTAP 2012: The Second International Conference on Digital Information and Communication Technology and its Applications - Bangkok, Thailand
Duration: 16 May 201218 May 2012

Conference

ConferenceDICTAP 2012: The Second International Conference on Digital Information and Communication Technology and its Applications
CityBangkok, Thailand
Period16/05/1218/05/12

Keywords

  • Computer System Security

Fingerprint

Dive into the research topics of 'Specification of Role and Attribute Transitions for Secure Information System Access'. Together they form a unique fingerprint.

Cite this