EMPIRICAL EVALUATION OF ROLE-BASED ACCESS CONTROL AND BELL- LA PADULA CONFIDENTIALITY SECURITY MODELS

  • A. A. Nureni
  • O. B. Okunoye
  • F. A. Oladeji
  • O. O. Vaughan

Abstract

Medical records are well known to contain vital, sensitive and treasurable information about patients and it is therefore important to guard them against any form of unpermitted or unauthorized access. The motive behind this paper is to benchmark Role Based Access Control (RBAC) and Bell-la Padula security models in a medical domain. Attempt was made to implement these models by evaluating their efficiencies, protection capacity, precision and speed. Role Base Access Control is a security model which allows a user at a higher level to access roles and permissions of a user at a lower level of his organization hierarchy. Bell-la Padula on the other hand uses the “no read-up, no write-down” method of implementation; that is, it does not allow a user at a higher level to write to a user at a lower level. Also, a user at a lower level cannot read up the hierarchy. Comparison of these two access control security models were evaluated in the medical domain based on the above listed metrics. The prototype of this work was implemented using Microsoft C# on the .Net framework with Microsoft’s SQL as the backend. The result shows the prototype of the RBAC models is better in terms of efficiency, protection capacity, precision and speed.

Author Biographies

A. A. Nureni

Department of Computer Sciences,

University of Lagos, Nigeria

O. B. Okunoye

Department of Computer Sciences,

University of Lagos, Nigeria

F. A. Oladeji

Department of Computer Sciences,

University of Lagos, Nigeria

O. O. Vaughan

Department of Computer Sciences,

University of Lagos, Nigeria

Published
2014-08-02
How to Cite
Nureni, A., Okunoye, O., Oladeji, F., & Vaughan, O. (2014). EMPIRICAL EVALUATION OF ROLE-BASED ACCESS CONTROL AND BELL- LA PADULA CONFIDENTIALITY SECURITY MODELS. LAUTECH Journal of Engineering and Technology, 8(2), 84-93. Retrieved from https://laujet.com/index.php/laujet/article/view/135
Section
Articles