Enabling the Deployment of ABAC Policies in RBAC Systems - 32th IFIP Annual Conference on Data and Applications Security and Privacy (DBSec) Access content directly
Conference Papers Year : 2018

Enabling the Deployment of ABAC Policies in RBAC Systems

Gunjan Batra
  • Function : Author
  • PersonId : 1040510
Vijayalakshmi Atluri
  • Function : Author
  • PersonId : 978120
Jaideep Vaidya
  • Function : Author
  • PersonId : 996030

Abstract

The flexibility, portability and identity-less access control features of Attribute Based Access Control (ABAC) make it an attractive choice to be employed in many application domains. However, commercially viable methods for implementation of ABAC do not exist while a vast majority of organizations use Role Based Access Control (RBAC) systems. In this paper, we present a way in which organizations having a RBAC system can deploy an ABAC policy. Thus, we propose a method for the translation of an ABAC policy into a form that can be adopted by an RBAC system. We compare the cost of enforcement in ABAC and RBAC with respect to time taken to evaluate an access request, and experimentally demonstrate that RBAC is significantly better in this respect. Since the cost of security management is more expensive under RBAC when compared to ABAC, we present an analysis of the different management costs and present mitigation approaches by considering various administrative operations.
Fichier principal
Vignette du fichier
470961_1_En_4_Chapter.pdf (511.39 Ko) Télécharger le fichier
Origin : Files produced by the author(s)
Loading...

Dates and versions

hal-01954419 , version 1 (13-12-2018)

Licence

Attribution

Identifiers

Cite

Gunjan Batra, Vijayalakshmi Atluri, Jaideep Vaidya, Shamik Sural. Enabling the Deployment of ABAC Policies in RBAC Systems. 32th IFIP Annual Conference on Data and Applications Security and Privacy (DBSec), Jul 2018, Bergamo, Italy. pp.51-68, ⟨10.1007/978-3-319-95729-6_4⟩. ⟨hal-01954419⟩
74 View
77 Download

Altmetric

Share

Gmail Facebook X LinkedIn More