Skip to main navigation Skip to search Skip to main content

A feature-based approach for modeling role-based access control systems

  • Sangsig Kim*
  • , Dae Kyoo Kim
  • , Lunjin Lu
  • , Suntae Kim*
  • , Sooyong Park
  • *Corresponding author for this work
  • Oakland University
  • Kangwon National University
  • Sogang University

Research output: Contribution to journalJournal articlepeer-review

Abstract

Role-based access control (RBAC) is a popular access control model for enterprise systems due to its flexibility and scalability. There are many RBAC features available, each providing a different function. Not all features are needed for an RBAC system. Depending on the requirements, one should be able to configure features on a need basis, which reduces development complexity and thus fosters development. However, there have not been suitable methods that enable systematic configuration of RBAC features for system development. This paper presents an approach for configuring RBAC features using a combination of feature modeling and UML modeling. Feature modeling is used for capturing the structure of features and configuration rules, and UML modeling is used for defining the semantics of features. RBAC features are defined based on design principles of partial inheritance and compatibility, which facilitates feature composition and verification. We demonstrate the approach using a banking application and present tool support developed for the approach.

Original languageEnglish
Pages (from-to)2035-2052
Number of pages18
JournalJournal of Systems and Software
Volume84
Issue number12
DOIs
StatePublished - 2011.12

Keywords

  • Feature modeling
  • Role-based access control
  • UML

Fingerprint

Dive into the research topics of 'A feature-based approach for modeling role-based access control systems'. Together they form a unique fingerprint.

Cite this