Search
Search Results
Found one item.
1 - 1 of 1 items
In the context of the rapid development of national-scale information systems and their evolution into digital ecosystems, new requirements are imposed on the process of ensuring the security of the information processed within them. These requirements include enhancing information availability in user access management while maintaining the required level of confidentiality, and making access decisions to resources based on multiple factors. To meet these requirements, numerous compositional access control models based on roles and attributes have been proposed previously, which have resolved several pressing issues while maintaining administrative convenience and providing flexibility and scalability without role explosion. However, known models still have a significant limitation – the impossibility of their use in information systems where high-sensitivity data is processed. The aim of the study is to develop, within the framework of the subject-object approach methodology in information security theory, a new mandatory role-centric attribute-based access control (MRABAC) model, as well as its formal description using the mathematical apparatus of automata theory. The use of the model will enable dynamic prevention of unauthorized information flows from high-confidentiality objects to low-confidentiality objects during the restriction of the permission set assigned to a role, through the implementation of mandatory access control via a separate attribute-based policy, while preserving the ability to provide users with fine-grained access based on contextual attributes. The application of the model may be particularly useful in large-scale information systems where information of various confidentiality levels is processed simultaneously, and, due to operational characteristics, attribute-based access control is necessary