作者
Narhimene Boustia, Aicha Mokhtari
发表日期
2008/3/4
研讨会论文
2008 Third International Conference on Availability, Reliability and Security
页码范围
1008-1012
出版商
IEEE
简介
In the organization based access control (ORBAC) model, to express security policy, it is necessary to make possible the system know which are the privileges of each user. The definition of permission should not be static, but it must depend on the requirement of the system, rules should be dynamic, depending on the context. Context is used to specify the concrete circumstances where user is given role permissions to perform activities on views. Formalization of ORBAC in a logical approach makes it feasible to reason about a specified policy and verifies its correctness. We propose a formal modelisation of ORBAC by the description logic language with default and exception AL deltaepsiv . We show how exception in information system security can be captured by AL deltaepsiv . We illustrate this approach by an example of a medical information system.
引用总数
2010201120122013201420152016201720182019202020212022323111112
学术搜索中的文章