Research on RBAC-based Separation of Duty Constraints
Authors
Abstract
Separation of duty (SOD) is an important characteristic in the role-based access control (RBAC)
system. In view of some issues such as various variations of SOD constraints (SODs), ambiguous relations
among constraint states, this paper formally defines several typical SODs and analyzes the transition relations
among different SODs states. In combination with a delegation case, it goes an exploration and discussion on
the SODs state transition issues, and proposes some corresponding solutions.