Context-aware Role-based Access Control Using Security Levels

Michal Trnka, Tomáš Černý · 2015

Security of software applications is a very challenging and extensive topic. to keep up with the trend of personalized context aware applications the security design must adapt to it. this paper presents context awareness into the role based access control. it will describe already existing solutions, point out their key ideas and propose our rbac lightweight extension. it is universal and allows instant enhancement of current rbac even in current applications. the proposed solution is based on security levels which are assigned to users based on context. security levels represent how the users can be trusted and they are determined during the login procedure. the levels are used as additional security constraints to access resources. in application, the user needs to possesses not only the right permission granted through rbac roles, but also have a corresponding level.

Read the paper · More papers on PaperTik