ABDM is a securer delegation model for it can restrict delegatee candidates more
strictly. ABDM
X
is more flexible than ABDM in delegation. For in ABDM
X
, a
delegator can temporarily delegate NMPs to low level users without causing any
security problems. Both ABDM and ABDM
X
can be used in temporary and
permanent delegation and make delegation securer and more flexible.
Further work includes supporting more constraints in ABDM and ABDM
X
, such
as separation of duty and cardinality, and revocation with DAE in them.
Acknowledgments
Our work is supported by The Research Fund for the Doctoral Program of Higher
Education (RFDP20040611002), China.
References
1. Ravi Sandhu, Edward Coyne, Hal Feinstein, Charles Younman, ‘Role-Based Access Control
Models’, IEEE Computer, Vol.29, 1996,pp.
38-47.
2. David F Ferraiolo, Ravi Sandhu, Serban Gavrila, ‘proposed standard for role-based access
control’, ACM Trans on information and System Security, Vol.4, 2001, pp.224-274.
3. Xinwen Zhang, Sejong Oh, Ravi Sandhu, ‘PBDM: A Flexible Delegation Model in RBAC’,
Proceedings of SACMAT’03, Como, Italy, 2003, pp.149-157.
4. Lynn Andrea Stein, ‘Delegation Is Inheritance’, proceedings Of Object-Priented
Programming Systems, Languages, and Applications (OOPSLA’87), New York, USA,
1987, pp.138-146.
5. J.D. Moffett, ‘Delegation of authority Using Domain Based Access Rules’, PhD Thesis,
Dept of Computing, Imperial College, University of London, 1990.
6. Morrie Gasser, Ellen McDermott 1990, ‘An Architecture for practical Delegation in a
Distributed System’, Proceedings of IEEE Computer Society Symposium on Research in
Security and Privacy. Oakland, USA, pp.20-30.
7. Ezedin Barka, Ravi Sandhu, ‘Framework for Role-Based Delegation Models’, Proceedings
of 16th Annual Computer Security Application Conference (ACSAC2000), New Orleans,
USA, 2000, pp.168-175
8. Ezedin Barka, Ravi Sandhu, ‘A role-based delegation model and some extensions’,
Proceedings Of 23rd National Information Systems Security Conference (NISSC),
Baltimore, USA, 2000, pp.101-114.
9. Longhua Zhang, Gail-Joon Ahn, Bei-Tseng Chu, ‘A rule-based framework for role-based
delegation’, proceedings of 6th ACM Symposium on Access Control Models and
Technologies (SACMAT), Chantilly, VA, 200, pp.153-162.
10. ZHAO Qing-Song, SUN Yu-Fang, SUN Bo, ‘RPRDM: A Repeated-and-Part-Role-Based
Delegation Model’, Journal of Computer Research and Development, Vol. 40, 2003,
pp.221-227.
11. Ravi S Sandhu, Venkata Bhamidipati, Qamar Munawerl, ‘The ARBAC97 model for role-
based administration of roles’, ACM Transaction s on Information and System Securty, Vol.
2, 1999, pp. 105-135.
12. Ravi Sandhu, Qamar Munawer, ‘the ARBAC99 model for administration of roles’,
Proceedings of the Annual Computer Security Applications Conference, Phoenix, USA,
1999.
158