Article

Purpose engineering for Contextual Role-Based Access Control (C-RBAC)

International Journal of Engineering 01/2008; DOI:http://www.doaj.org/doaj?func=openurl&genre=article&issn=19852312&date=2008&volume=2&issue=3&spage=41
Source: DOAJ

ABSTRACT Distributed and ubiquitous computing environments have brought enormous efficiency to the collection, manipulation and distribution of information and services. Although this efficiency has revolutionized countless organizations but it has also increased the threats to individual’s privacy because the information stored within the collection of heterogeneous distributed components is sensitive and requires some form of access control. The way to protect privacy in this age of information technology requires such access control system that can accommodate organization requirements to protect privacy of individuals with ease in management and administration of resources. Among those requirements, purpose inference is one of the major problems as the total access control decision mainly relies on the user intentions/purposed. This work in this paper is an attempt to provide purpose engineering semantics that we use for the proposed contextual role-based access control model (C-RBAC) in order to comply with HIPAA.

0 0
 · 
0 Bookmarks
 · 
68 Views

Full-text

View
0 Downloads
Available from

Keywords

access control
 
access control system
 
C-RBAC
 
Distributed
 
enormous efficiency
 
heterogeneous
 
HIPAA
 
information technology
 
major problems
 
organization requirements
 
proposed contextual role-based access control model
 
purpose engineering semantics
 
purpose inference
 
total access control decision
 
user intentions/purposed