Extended Request-oriented Role Access Control Model for Web Applications

Dmitry KONONOV, Sergey ISAEV

Abstract


This work is dedicated to developing security access control model for web applications. Our work is focused on RBAC model described by Ferraiolo and Kuhn [1992] and Sandhu [1998]. This article describes the new request-oriented RBAC model, which allows flexible access control using web request path and parameters. The new model is a development of our previous extended path-based RBAC model and provides additional access control capabilities. Applying this new model allows reducing security risks for web applications.

Keywords


Web, Security, Access control, Roles, RBAC


DOI
10.12783/dtcse/cmee2017/19958

Refbacks

  • There are currently no refbacks.