9 Access Control Systems for Geospatial Data and Applications
193
granting and revoking authorizations. It is the function by which authorizations are
entered (removed) into (from) the ACS. Common administration policies include the
centralized administration policy, by which only some privileged users may grant
and revoke authorizations, and the ownership-based administration, by which grant
and revoke operations on a data objects are issued by the creator of the object. The
ownership-based administration is often extended with features for administration
delegation. Administration delegation allows the owner of an object to assign other
users the right to grant and revoke authorizations, thus enabling decentralized authorization administration.
Role-based Access Control
Role-based access control is centered on the notion of role. A role is a semantic
construct which represents a job function within an organization. Specifically, the
RBAC standard consists of four basic sets of elements: users, roles, permissions, and
sessions.
• User is as a human being or an autonomous agent.
• Role represents the function of a user within a community. The community can
be a structured organization, for example, a business enterprise or a more informal community, for example the citizens of a city. A role confers a set of
permissions on the user.
• Permission. Permission is an approval to perform an operation on one or more
objects. An object is a resource that shall be protected. An operation is an
executable image of a program, which on invocation executes some function
for the user over some object. The types of operations and objects depend on the
application context in which RBAC is deployed. For example, in a file system,
operations might include read, write, and execute; in a DBMS, operations might
include insert, delete, append, and update.
• Session. When the user logs in, a session is established, during which the user
activates some subset of roles that he or she is assigned. The permissions available to the user of the session are thus the permissions assigned to the roles that
are currently active across all the user’s sessions.
Over the above sets of elements, a number of relations are defined. The user
assignment relates users to roles through a many-to-many relationship, a user can
therefore be assigned multiple roles and the same role assigned to different users. The
permission-assignment relation relates roles and permissions again through a manyto-many relationship; thus a role can be assigned multiple permissions and similarly
each permission can be assigned to multiple roles. The function SessionUser maps
each session into a user, whereas the SessionRole function maps a session onto a
set of roles, namely the roles that are active in the session. The basic concepts are
formally summarized as follows:
Definition 9.1 (Basic Concepts of RBAC ). Let U, R, PRMS, and SES denote the
set of users, roles, permissions, and sessions, respectively. We define:
Précédent

- 186/317

Suivant