IMPROVING ACCESS RESTRICTIONS IN COMMERCIAL BANKS INFORMATION SYSTEMS USING A MODIFIED ROLE-BASED METHOD
Keywords:
Information security, access control, RBAC, ABAC, hybrid access control, commercial banks, information system, access rights, attributes, role model.Abstract
This article considers the issue of eliminating the existing shortcomings of the role-based access control (RBAC) method, which is widely used in the process of access control in information systems of commercial banks. In order to reduce these shortcomings, a modified (hybrid) approach based on a combination of RBAC and attribute-based access control (ABAC) methods is proposed. The proposed method allows determining access rights taking into account the roles of users, as well as their attributes, resource attributes and system attributes. The article develops a mathematical model of the modified method, a set of basic parameters and an algorithm designed for information systems of commercial banks. The proposed approach increases flexibility in the use of bank information resources, enhances the level of security and reduces the risk of unauthorized access.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution 4.0 International License.
You are free to:
- Share — copy and redistribute the material in any medium or format for any purpose, even commercially.
- Adapt — remix, transform, and build upon the material for any purpose, even commercially.
- The licensor cannot revoke these freedoms as long as you follow the license terms.
Under the following terms:
- Attribution — You must give appropriate credit , provide a link to the license, and indicate if changes were made . You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use.
- No additional restrictions — You may not apply legal terms or technological measures that legally restrict others from doing anything the license permits.
Notices:
You do not have to comply with the license for elements of the material in the public domain or where your use is permitted by an applicable exception or limitation .
No warranties are given. The license may not give you all of the permissions necessary for your intended use. For example, other rights such as publicity, privacy, or moral rights may limit how you use the material.