Budget-aware role based access control

Farzad Salim, Jason Reid, Uwe Dulleck, Ed Dawson

Research output: Contribution to journalArticlepeer-review

10 Citations (Scopus)


The suitability of Role Based Access Control (RBAC) is being challenged in dynamic environments like healthcare. In an RBAC system, a user's legitimate access may be denied if their need has not been anticipated by the security administrator at the time of policy specification. Alternatively, even when the policy is correctly specified an authorised user may accidentally or intentionally misuse the granted permission. The heart of the challenge is the intrinsic unpredictability of users' operational needs as well as their incentives to misuse permissions. In this paper we propose a novel Budget-aware Role Based Access Control (B-RBAC) model that extends RBAC with the explicit notion of budget and cost, where users are assigned a limited budget through which they pay for the cost of permissions they need. We propose a model where the value of resources are explicitly defined and an RBAC policy is used as a reference point to discriminate the price of access permissions, as opposed to representing hard and fast rules for making access decisions. This approach has several desirable properties. It enables users to acquire unassigned permissions if they deem them necessary. However, users misuse capability is always bounded by their allocated budget and is further adjustable through the discrimination of permission prices. Finally, it provides a uniform mechanism for the detection and prevention of misuses.

Original languageEnglish
Pages (from-to)37-50
Number of pages14
JournalComputers and Security
Publication statusPublished - Jun 2013
Externally publishedYes


Dive into the research topics of 'Budget-aware role based access control'. Together they form a unique fingerprint.

Cite this