Skip to main navigation Skip to search Skip to main content

Supporting Parameterised Roles with Object-based Access Control

Mark Peter Evered

Research output: Chapter in Book/Report/Conference proceedingConference contribution

1 Citation (Scopus)

Abstract

The per-method access control lists of standard internet technologies allow only simple forms of access control to be expressed and enforced. They also fail to enforce a strict need-to-know view of persistent data. Real applications require more flexible security constraints including parameter restrictions, logging of accesses and state-dependent access constraints. In particular, the concept of parameterised roles, central to a fine-grained specification of access rules and compliance with privacy laws, should be supported in a natural way. In this paper we demonstrate how an object-based approach using the mechanism of bracket capabilities can be used to enforce various kinds of access constraints including discretionary, mandatory and parameterised role-based access control. We give examples from a health information system incorporating secure patient access and secure access by appropriate medical and administrative personnel.
Original languageEnglish
Title of host publicationProceedings of the 36th Annual Hawaii International Conference on System Sciences
EditorsR H Sprague Jr
Place of PublicationLos Alamitos, United States of America
PublisherInstitute of Electrical and Electronics Engineers (IEEE)
Pages1-9
ISBN (Print)0769518745
DOIs
Publication statusPublished - 2003
EventHICSS-36 (2003): 36th Annual Hawaii International Conference on System Sciences - Waikoloa, United States of America
Duration: 6 Jan 20039 Jan 2003

Conference

ConferenceHICSS-36 (2003): 36th Annual Hawaii International Conference on System Sciences
CityWaikoloa, United States of America
Period6/01/039/01/03

Keywords

  • Data Format

Fingerprint

Dive into the research topics of 'Supporting Parameterised Roles with Object-based Access Control'. Together they form a unique fingerprint.

Cite this