Analysing Conflict of Interest Integrated in Role-Based Access Control Model Using Event-B
摘要
Role-Based Access Control (RBAC) is a well-known access control model that restricts system access to authorized users based on their assigned roles within an organization. However, vulnerabilities in software systems often arise from conflicts of interest, as involved parties may exploit their positions or roles within the system to achieve personal gain. In order to overcome this problem, the paper proposes an approach for analysing Conflict of Interest integrated in the Role-Based Access Control mechanism of a software system model using Event-B. With the approach, system designers can specify and verify systematically the properties of conflicts of interest that may arise within the organization’s software systems. Additionally, modeling and verifying during the requirements analysis phase can help software developers detect errors early, ensuring the accuracy of the software design. The approach is illustrated through a case study, focused on the credit process scenario within a banking application.