Back to Search Start Over

Smatch: Formal dynamic session management model for RBAC.

Authors :
Cuppens, Frédéric
Cuppens-Boulahia, Nora
Ben Ghorbel-Talbi, Meriam
Morucci, Stéphane
Essaouni, Nada
Source :
Journal of Information Security & Applications. Jul2013, Vol. 18 Issue 1, p30-44. 15p.
Publication Year :
2013

Abstract

This paper extends RBAC sessions with shareability, reusability and switchability properties. We define the Smatch (Secure MAnagement of swiTCH) model in which authorized users can join, leave, reopen and reuse dynamic sessions. In Smatch, subjects can also share sessions and dynamically switch their role or function with other subjects from the same or different organizations. Subjects can authenticate using their function which will automatically activate the set of roles associated with this function. The Smatch model is based on the situation calculus which extends first order logic with actions. It provides means to specify contextual access control and authentication policies which apply to control functional behavior of dynamic sessions. We formally analyze decidability and complexity of several problems like decision, planning and proof of properties in the Smatch model. We also suggest an implementation of Smatch using Eyeos, an open-source web based Operating System. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
22142126
Volume :
18
Issue :
1
Database :
Academic Search Index
Journal :
Journal of Information Security & Applications
Publication Type :
Academic Journal
Accession number :
162176741
Full Text :
https://doi.org/10.1016/j.jisa.2013.07.001