/
Kuhn, 1998

Kuhn, 1998

Role based access control on MLS systems without kernel changes

Type

Article

Year

1998

Authors

Kuhn, D.R.

Identifiers

Abstract

Role based access control (RBAC) is attracting increasing attention as a security mechanism for both commercial and many military systems. This paper shows how RBAC can be implemented using the mechanisms available on traditional multi-level security systems that implement information flow policies. The construction from MLS to RBAC systems is significant because it shows that the enormous investment in MLS systems can be leveraged to produce RBAC systems. The method requires no changes to the existing MLS system kernel and allows implementation of hierarchical RBAC entirely through site configuration options. A single trusted process is used to map privileges of RBAC roles to MLS labels. Access is then mediated by the MLS kernel. Where C is the number of categories and d the depth of the role hierarchy, the number of roles that can be controlled is approximately
(C /d C /2d )d

(Kuhn, 1998, p. 1)

Links

Citation

Kuhn, D.R., 1998. Role based access control on MLS systems without kernel changes, in: Proceedings of the Third ACM Workshop on Role-Based Access Control  - RBAC ’98. Presented at the the third ACM workshop, ACM Press, Fairfax, Virginia, United States, pp. 25–32. https://doi.org/10.1145/286884.286890

 

Related content

Ferraiolo, 1995
Ferraiolo, 1995
More like this
Sandhu, 1998
Sandhu, 1998
More like this
Sandhu, 1996
Sandhu, 1996
More like this
Ferraiolo et al., 2007
Ferraiolo et al., 2007
More like this
Benantar, 2006
Benantar, 2006
More like this
Kunz et al., 2010
Kunz et al., 2010
More like this

Follow us on LinkedIn | Discuss on Slack | Support us with Patreon | Sign-up for a free membership.


This wiki is owned by Open Measure, a non-profit association. The original content we publish is licensed under a Creative Commons Attribution 4.0 International License.