期刊名称:International Journal of Innovative Research in Computer and Communication Engineering
印刷版ISSN:2320-9798
电子版ISSN:2320-9801
出版年度:2014
卷号:2
期号:8
出版社:S&S Publications
摘要:With the development of Internet and Intranet, Web and distributed databases have been used more andmore widely. It is important to properly handle network and Web database security issues including authentication,denial of service, and fine-grained access control. When database access control and the network security are addressedseparately, the security systems are not optimized sufficiently as a whole. This paper presents a Criterion-Based Role-Based Access Control model in which secure permissions (SP), secure operations (SOp), secure objects (SOb), andsecure users (SU) are introduced. The security criterion expressions (SCE) embedded in SOb work as locks and thecommon elements of the security criterion subsets (SCSS) in Sop and SU work as keys. To support web-basedapplications, the remote secure user-role assignment is done based on user‟s digital credential(s), and Compact-SecureRole-SCSS cookies are adopted to simplify the subsequent transactions. The multilayer access control is achieved byactuating locks with the relevant keys. The proposed model, an extension of traditional RBAC, efficiently supportsboth multilayer access control and non-multilayer access control on the web.