Abstract
Role-based access control (RBAC) is a popular access control model for enterprise systems due to its flexibility and scalability. There are many RBAC features available, each providing a different function. Not all features are needed for an RBAC system. Depending on the requirements, one should be able to configure features on a need basis, which reduces development complexity and thus fosters development. However, there have not been suitable methods that enable systematic configuration of RBAC features for system development. This paper presents an approach for configuring RBAC features using a combination of feature modeling and UML modeling. Feature modeling is used for capturing the structure of features and configuration rules, and UML modeling is used for defining the semantics of features. RBAC features are defined based on design principles of partial inheritance and compatibility, which facilitates feature composition and verification. We demonstrate the approach using a banking application and present tool support developed for the approach.
| Original language | English |
|---|---|
| Pages (from-to) | 2035-2052 |
| Number of pages | 18 |
| Journal | Journal of Systems and Software |
| Volume | 84 |
| Issue number | 12 |
| DOIs | |
| State | Published - 2011.12 |
Keywords
- Feature modeling
- Role-based access control
- UML
Fingerprint
Dive into the research topics of 'A feature-based approach for modeling role-based access control systems'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver