TY - GEN
T1 - Zoned Role-Based Approach to System Design, Implementation, and Access Control of Integrated Web Applications
AU - Wang, Harris
N1 - Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2025.
PY - 2025
Y1 - 2025
N2 - In today’s world almost all organizations heavily depend on Web-based systems or web applications for their day-to-day operations. In this paper, we will present zoned role-based (ZRB) approach to the design and implementation of integrated web-based systems for organizations and enterprises. In contrast to Role-Based Access Control (RBAC), well-known in computer security, this approach can be used throughout the entire life cycle of a web-based system, and can make the design, implementation, deployment and maintenance of integrated web system more efficient and effective for all organizations and enterprises. In this approach, areas of business, or divisions, departments or designated groups of employees for specific missions are called zones, and for each zone a set of roles are defined; for each role, some web apps, each of which consists of a set of operations, are designed and implemented for users in their respective roles to conduct their business in each associated zone; and control of user access to each operation can then be done explicitly by associating each operation with roles by inference based on the relationships between roles. Within such a zoned role-based integrated system, once a user has roles assigned in each zone he or she is affiliated, he will be able to access, precisely, all the apps and operations needed to fulfill his or her role or roles in respective zone, with only one authentication. Such integration is rather important and convenient especially when users may be affiliated with multiple zones or play multiple roles.
AB - In today’s world almost all organizations heavily depend on Web-based systems or web applications for their day-to-day operations. In this paper, we will present zoned role-based (ZRB) approach to the design and implementation of integrated web-based systems for organizations and enterprises. In contrast to Role-Based Access Control (RBAC), well-known in computer security, this approach can be used throughout the entire life cycle of a web-based system, and can make the design, implementation, deployment and maintenance of integrated web system more efficient and effective for all organizations and enterprises. In this approach, areas of business, or divisions, departments or designated groups of employees for specific missions are called zones, and for each zone a set of roles are defined; for each role, some web apps, each of which consists of a set of operations, are designed and implemented for users in their respective roles to conduct their business in each associated zone; and control of user access to each operation can then be done explicitly by associating each operation with roles by inference based on the relationships between roles. Within such a zoned role-based integrated system, once a user has roles assigned in each zone he or she is affiliated, he will be able to access, precisely, all the apps and operations needed to fulfill his or her role or roles in respective zone, with only one authentication. Such integration is rather important and convenient especially when users may be affiliated with multiple zones or play multiple roles.
KW - Integrated web apps development
KW - Software development methodology
KW - Zoned role-based access control
KW - Zoned role-based system development
UR - http://www.scopus.com/inward/record.url?scp=85207847853&partnerID=8YFLogxK
U2 - 10.1007/978-3-031-75201-8_4
DO - 10.1007/978-3-031-75201-8_4
M3 - Published Conference contribution
AN - SCOPUS:85207847853
SN - 9783031752001
T3 - Communications in Computer and Information Science
SP - 43
EP - 54
BT - Software and Data Engineering - 33rd International Conference, SEDE 2024, Proceedings
A2 - Feng, Wenying
A2 - Rahimi, Nick
A2 - Margapuri, Venkatasivakumar
T2 - 33rd International Conference on Software and Data Engineering, SEDE 2024
Y2 - 21 October 2024 through 22 October 2024
ER -