Computer Science ›› 2017, Vol. 44 ›› Issue (8): 140-145.doi: 10.11896/j.issn.1002-137X.2017.08.025

Dynamic Business-oriented Access Control Model

TAN Ren, YIN Xiao-chuan, LI Xiao-hui and BIAN Yang-yang   

  • Online:2018-11-13 Published:2018-11-13

Abstract: Aiming at the problems of rough-grained access control and unable to adjust authorization dynamically in business process of traditional role-based access control (RBAC) model,a business-oriented dynamic RBAC model (BO-RBAC) was proposed in this paper.Taking TBAC model as reference,business step and authorization step are introduced into this model and basic model set is defined formally.Meanwhile,the authorization process is divided into two parts,role authorization and step authorization,and the execution is regarded as random process which shows a Markov chain-based dynamic authorization method.Finally,the model is implemented with C++14 programming language.BO-RBAC model combines the features of RBAC and TBAC,which introduces such advantages of fine-grained access control,dynamically-adjusting authorization and satisfy security specifications.

Key words: RBAC,TBAC,Dynamic authorization,Access control,Markov state machine

