INCITS 494-2012

Information Technology – Role Based Access Control – Policy-Enhanced


 

 

非常抱歉,我们暂时无法提供预览,您可以试试: 免费下载 INCITS 494-2012 前三页,或者稍后再访问。

如果您需要购买此标准的全文,请联系:

点击下载后,生成下载文件时间比较长,请耐心等待......

 

标准号
INCITS 494-2012
发布日期
2012年07月26日
实施日期
2018年04月28日
废止日期
中国标准分类号
/
国际标准分类号
/
发布单位
ANSI - American National Standards Institute
引用标准
27
适用范围
Role Based Access Control (RBAC) has been criticized for the difficulty of setting up an initial role structure and for inflexibility in rapidly changing domains. A pure RBAC solution may provide inadequate support for dynamic attributes@ such as time of day@ which might need to be considered when determining user permissions. This RBAC Policy-Enhanced standard (to be referenced as RPE) provides a framework and functional specifications to handle the relationship between roles and dynamic constraints. Some of the administrative and user permission review advantages of RBAC are retained while allowing the access control system to work in a rapidly changing environment. The RPE defines the scope and context for role-role@ user-role@ and attribute-sensitive dynamic constraints which can be implemented in a run-time environment. This standard defines the functional areas of External Policy Interfaces@ the RBAC Engine@ and enhanced dynamic constraint mechanisms of the RBAC Policy-Enhanced Reference Model. Additional interfaces have been included to provide visibility into the system for integrity checking (RBAC Implementation and Interoperability Interface) and Audit Monitoring of the RPE access control model. These RPE features extend the dynamic constraints of RBAC (INCITS 359-2012)@ which primarily emphasize Separation of Duty (SoD) functions. The RPE allows external policies (rules and data) to implement constraints on the core role components within the base RBAC Reference Model (INCITS 359-2012) and define dynamic constraints which may be applied to users@ roles@ operations@ objects@ and permissions. These enhancements are defined through several mechanisms including an RBAC Engine algorithm@ supporting system functions for the RBAC Engine@ an external security policy interface and the definitions of dynamic constraint primitives and operations. These combined features enable the RPE to define and implement the least privilege conditions (fine-grained authorization) necessary to tailor the base RBAC Reference Model to various attributes and dynamic constraints. Extending the static constraints of RBAC (INCITS 359-2012)@ the RPE also defines static constraints@ which consist of role-role@ permission-permission@ permission-role@ and user-role constraints. Static constraints are constraints that take effect prior to run time and are enforced by administrative processes. Informative Annex A provides references for this document. Informative Annex B presents the table of RBAC Implementation and Interoperability Standard (RIIS) Management Functions@ which are commands for reviewing the status of the RBAC Engine described in this work.




Copyright ©2007-2022 ANTPEDIA, All Rights Reserved
京ICP备07018254号 京公网安备1101085018 电信与信息服务业务经营许可证:京ICP证110310号