Abstract:
A new role based access control model is proposed, which extends the traditional role based access control (RBAC) model Based on the abstraction of the user properties relevant to security in traditional RBAC model, the new model adds the abstraction of the object properties and access properties relevant to security Using the traditional concept of role, it incorporates these properties into the access decision and enhances RBAC’s power and function The characteristics of the new model include simpleness, flexibility, power expression ability, and strong usability Also it is closer to the real world than the traditional RBAC model After giving a formal definition of the new model, its implementation method is studied and the structure of model implementation, the monitor mechanism of role assignment, and the access decision policy are presented