错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Analysing Conflict of Interest Integrated in Role-Based Access Control Model Using Event-B

  • Thanh-Binh Trinh,
  • Van-Khanh To,
  • Ninh-Thuan Truong,
  • Hong Anh Le

摘要

Role-Based Access Control (RBAC) is a well-known access control model that restricts system access to authorized users based on their assigned roles within an organization. However, vulnerabilities in software systems often arise from conflicts of interest, as involved parties may exploit their positions or roles within the system to achieve personal gain. In order to overcome this problem, the paper proposes an approach for analysing Conflict of Interest integrated in the Role-Based Access Control mechanism of a software system model using Event-B. With the approach, system designers can specify and verify systematically the properties of conflicts of interest that may arise within the organization’s software systems. Additionally, modeling and verifying during the requirements analysis phase can help software developers detect errors early, ensuring the accuracy of the software design. The approach is illustrated through a case study, focused on the credit process scenario within a banking application.