A TASK-BASED AUTHORIZATION MODEL
-
-
Abstract
Classical subject-object view of access control is no longer suitable for security issues in information processing activities with multiple points of access control because of the difference between the commercial information system and the military information system. A formal description of a new authorization policy, the task-based authorization, is presented in this paper. The fundamental properties, rules and operations of the model are defined by adoption of set and relation concept. Its security analysis is given at the end of the paper. In this model, authorization doesn’t simply behave through static tuple of (s, o, a) but has lifecycle during which its status will be changed with the execution of task instance. The model also enables granting permission, tracking usage of materials and revoking permissions to be automated, and coordinates the proceeding of various task instances.
-
-