Changes between Version 3 and Version 4 of Internal/Rbac/OrbitRbacDesign/OasisRbac
- Timestamp:
- Sep 1, 2006, 6:55:08 PM (19 years ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
- 
      Internal/Rbac/OrbitRbacDesign/OasisRbacv3 v4 2 2 === OASIS RBAC === 3 3 Presently OASIS only supports core and hierarchical RBAC, but not static and dynamic sepraration of duty. As stated in the abstract of [[http://orbit-lab.org/attachment/wiki/Internal/Rbac/RbacResources/access_control-xacml-2.0-rbac-profile1-spec-os.pdf Com05a]] Core and Hierarchical Role Based Access Control (RBAC) Profile of XACML, v2.0: 4 This specification defines a profile for the use of XACML in expressing policies that use role based access control (RBAC). It extends the XACML Profile for RBAC Version 1.0 to include a recommended AttributeId for roles, but reduces the scope to address only core and hierarchical RBAC. This specification has also been updated to apply to XACML 2.0.4 This specification defines a profile for the use of XACML in expressing policies that use role based access control (RBAC). It extends the XACML Profile for RBAC Version 1.0 to include a recommended !AttributeId for roles, but reduces the scope to address only core and hierarchical RBAC. This specification has also been updated to apply to XACML 2.0. 5 5 6 6 Later, on page 4 in Section 1.3 Scope: 7 The policies specified in this profile assume all the roles for a given subject have already been enabled at the time an authorization decision is requested. They do not deal with an environment in which roles must be enabled dynamically based on the resource or actions a subject is attempting to perform. For this reason, the policies specified in this profile also do not deal with static or dynamic Separation of Duty (see [ANSI-RBAC]). A future profile may address the requirements of this type of environment. 7 The policies specified in this profile assume all the roles for a given subject have already been enabled at the time an authorization decision is requested. They do not deal with an environment in which roles must be enabled dynamically based on the resource or actions a subject is attempting to perform. For this reason, the policies specified in this profile also do not deal with static or dynamic Separation of Duty (see 8 [[http://orbit-lab.org/attachment/wiki/Internal/Rbac/RbacResources/ANSI+INCITS+359-2004.pdf ANSI-RBAC]]). A future profile may address the requirements of this type of environment. 8 9 9 10 [[Jat Singh's review http://www.srcf.ucam.org/~js573/research/index.php?option=com_content&task=view&id=64&Itemid=49]] 

