Take a sneak peek at the new NIST.gov and let us know what you think!
(Please note: some content may not be complete on the beta site.).
NIST Authors in Bold
|Title:||A Revised Model for Role-Based Access Control|
|Published:||July 09, 1998|
|Abstract:||Role Based Access Control (RBAC) refers to a class of security mechanisms that mediate access to resources through organizational identities called roles. A number of models have been published that formally describe the basic properties of RBAC. This report focuses on an RBAC model originally proposed by Ferraiolo and others at NIST, and formulates a revised model that fixes noted discrepancies, incorporates features from related models, and addresses new properties regarding role hierarchies. Possible future extensions to the revised model and the motivation for them are also discussed. Finally, a subset of the properties defined in the revised model is proposed as the criteria for determining whether an implementation should be classified as an RBAC system.|
|Citation:||NIST Interagency/Internal Report (NISTIR) - 6192|
|Keywords:||formal models, RBAC, Role Based Access Control, security mechanisms|
|Research Areas:||Computer Security|
|PDF version:||Click here to retrieve PDF version of paper (91KB)|