Prathima Rao, Dan Lin, et al.
POLICY 2008
A privacy-aware role-based access control (P-RBAC) model that extends RBAC to express complex privacy-related policies, including such features as conditions and obligations is discussed. P-RBAC is easy to deploy in systems already adopting RBAC, thus allowing seamless integration of access control and privacy policies. Conditional P-RBAC introduces permission assignment sets and complex Boolean expressions. It can express more complex conditions than those supported by core P-RBAC's condition language. Hierarchical P-RBAC introduces the notions of role hierarchy, object hierarchy, and purpose hierarchy. P-RBAC can represent privacy law rules with obligations using a rule from COPPA. P-RBAC features method that deals with obligations with subject binding instead of action binding.
Prathima Rao, Dan Lin, et al.
POLICY 2008
Amani Abu Jabal, Maryam Davari, et al.
IEEE-TSC
Gregory H. Cirincione, Dinesh Verma, et al.
FUSION 2018
Yuqing Sun, Qihua Wang, et al.
IEEE TDSC