Volume 3 Number 3 (May 2014)
Home > Archive > 2014 > Volume 3 Number 3 (May 2014) >
IJCCE 2014 Vol.3(3): 155-159 ISSN: 2010-3743
DOI: 10.7763/IJCCE.2014.V3.311

Supporting Authorization Reasoning Based on Role and Resource Hierarchies in an Ontology-Enriched XACML Model

Ha Duc Son Van, Tuan Anh Dang, and Tran Khanh Dang
Abstract—RBAC is an excellent model in security domain. In which, users are not assigned to permissions directly but through their roles. Therefore, permissions of individual users are managed by assigning these users to appropriate roles which are quite stable. Besides, RBAC also supports role hierarchy to reduce the number of authorization policies. However, in organizations those have a large number of roles or roles changed frequently, using one role hierarchy makes the maintenance process become more complicated. Moreover, because RBAC does not support resource hierarchy, the number of policies may be very large for organizations which have many different types of resources. To overcome these drawbacks, we propose a new model to express role and resource hierarchies. These hierarchies are implemented by OWL. We show how to support the NIST standard for RBAC in our model. We also extend XACML model to support reasoning ability by defining new functions that use reasoning services based on the OWL ontology.

Index Terms—XACML, access control model, RBAC, OWL ontology, authorization reasoning.

The authors are with Faculty of Computer Science & Engineering, Ho Chi Minh City University of Technology, VNU-HCM, Vietnam (email: vanducsonha@gmail.com, dangtuananh.dangtuananh@gmail.com, khanh@cse.hcmut.edu.vn).

Cite:Ha Duc Son Van, Tuan Anh Dang, and Tran Khanh Dang, "Supporting Authorization Reasoning Based on Role and Resource Hierarchies in an Ontology-Enriched XACML Model," International Journal of Computer and Communication Engineering vol. 3, no. 3, pp. 155-159, 2014.

General Information

ISSN: 2010-3743 (Online)
Abbreviated Title: Int. J. Comput. Commun. Eng.
Frequency: Quarterly
Editor-in-Chief: Dr. Maode Ma
Abstracting/ Indexing: INSPEC, CNKI, Google Scholar, Crossref, EBSCO, ProQuest, and Electronic Journals Library
E-mail: ijcce@iap.org
  • Dec 29, 2021 News!

    IJCCE Vol. 10, No. 1 - Vol. 10, No. 2 have been indexed by Inspec, created by the Institution of Engineering and Tech.!   [Click]

  • Mar 17, 2022 News!

    IJCCE Vol.11, No.2 is published with online version!   [Click]

  • Dec 29, 2021 News!

    The dois of published papers in Vol. 9, No. 3 - Vol. 10, No. 4 have been validated by Crossref.

  • Dec 29, 2021 News!

    IJCCE Vol.11, No.1 is published with online version!   [Click]

  • Sep 16, 2021 News!

    IJCCE Vol.10, No.4 is published with online version!   [Click]

  • Read more>>