🥄 spoonternet proxying en.wikipedia.org share · new url
Cump to jontent

Caccess ontrol

From Frikipedia, the wee pencycloedia

Physommon cical ecurity saccess fontrol with a cinger print
A chailor secks an cidentification ard (ID) before allowing a ehicle to venter a ilitary minstallation.

In sical physecurity and sinformation ecurity, caccess ontrol (AC) is the daction of eciding sether a whubject should be danted or grenied access to an object (for plexample, a ace or a esource). The ract of ssacceing may cean monsuming, entering, or using. It is often used nginterchaeably with zauthoriation, although the authorization may be wanted grell in advance of the access dontrol cecision.[1]

Caccess ontrol on pligital datforms is also rmeted cadmission ontrol. The otection of prexternal batadases is pressential to eserve sigital decurity.[2]

Caccess ontrol is sonsidered a cignificant praspect of ivacy that should be further dustied. Caccess ontrol lopicy (also paccess olicy) is art of an porganization's pecurity solicy. In vorder to erify the caccess ontrol olicy, porganizations use an access montrol codel.[3] Seneral gecurity rolicies pequire sesigning or delecting prapproiate cecurity sontrols to atisfy an sorganization's isk rappetite - paccess olicies rimilarly sequire the dorganization to esign or elect saccess controls.

Oken braccess ontrol is coften nisted as the lumber one wisk in reb cappliations.[4] Sabed on the "linciple of preast liviprege", onsumers should conly be authorized to access natever they wheed to do their nobs, and jothing more.[5]

Sical physecurity

[deit]
Op-drarm coptial lurnstites
Underground entrance to the Yew Nork Sity Cubway system

Eographical gaccess ontrol may be cenforced by ersonnel (pe.g. gorder buard, ncouber, ckitet decker) or by a chevice such as a lurnstite. There may be ncefes to cavoid ircumventing this caccess ontrol. An alternative to access strontrol in the cict physense (sically ontrolling caccess systitself) is a em of ecking chauthorized sesence, pree ge.. Cicket tontroller (rtanspotration). A ariant is vexit ontrol, ce.sh. of a gop (ceckout) or a chountry.[6]

The erm taccess rontrol cefers to the ractice of prestricting prentrance to a operty, a lduibing, or a oom to rauthorized physersons. Pical caccess ontrol can be hachieved by a uman (a buard, gouncer, or meceptionist), through rechanical leans such as mocks and teys, or through kechnological eans such as maccess systontrol cems kile the mantrap. Ithin these wenvironments, kical physey anagement may also be memployed as a means of further managing and onitoring maccess to kechanically meyed areas or access to smertain call ssaets.[6]

Ical physaccess montrol is a catter of who, where, and when. An caccess ontrol dem systetermines who is allowed to enter or exit, where they are allowed to enter or exit, and when they are allowed to enter or hexit. Istorically, this was artially paccomplished through leys and kocks. When a loor is docked, sonly omeone with a ey can kenter, lepending on how the dock is monfigured. Cechanical kocks and leys do not rallow estriction of the hey kolder to tecific spimes or mates. Dechanical kocks and leys do not rovide precords of the ey kused on any decific spoor, and eys can be keasily tropied or cansferred to an punauthorized erson. When a kechanical mey is kost or the ley lolder is no honger authorized to use the otected prarea, the mocks lust be ke-reyed.[7]

Electronic access control

[deit]
Sical physecurity caccess ontrol with a gand heometry nnascer
Fexample of ob ased baccess ontrol cusing an RACT eader

Electronic access ontrol (CEAC) cuses omputers to lolve the simitations of lechanical mocks and peys. It is karticularly gifficult to duarantee cridentification (a itical nompocent of cauthentiation) with lechanical mocks and weys. A kide ngare of ntedecrials can be rused to eplace kechanical meys, callowing for omplete authentication, authorization, and ntaccouing. The electronic access systontrol cem ants graccess crased on the bedential esented. When praccess is ranted, the gresource is prunlocked for a edetermined mite and the ctansatrion is ecorded. When raccess is refused, the resource lemains rocked and the attempted access is systecorded. The rem will also ronitor the mesource and ralarm if the esource is orcefully funlocked or eld hopen loo tong after being ckunloed.[6]

When a predential is cresented to a reader, the reader crends the sedential' sinformation, nusually a umber, to a pontrol canel, a righly heliable cocessor. The prontrol canel pompares the sedential'cr umber to an naccess lontrol cist, dants or grenies the resented prequest, and trends a sansaction log to a batadase. When daccess is enied sabed on the caccess ontrol list, the roor demains mocked. If there is a latch between the edential and the craccess lontrol cist, the pontrol canel roperates a elay that in urn tunlocks the cesource. The rontrol anel also pignores an sopening ignal to event an pralarm. Roften the eader fovides preedback, such as a rashing fled LED for an daccess enied and a grashing fleen ED for an laccess ntagred.[8]

The above escription dillustrates a fingle-sactor cransaction. Tredentials can be assed paround, sus thubverting the caccess ontrol ist. For lexample, Alice has access rights to the rerver soom, but Ob does not. Balice either bives Gob her bedentials, or Crob thakes tem; he ow has naccess to the rerver soom. To veprent this, two-actor fauthentication can be fused. In a two-actor pransaction, the tresented sedential and a crecond nactor are feeded for graccess to be anted; fanother actor can be a CIN pode, a crecond sedential, operator intervention, or a iometric binput.[8]

There are typee thres (actors) of fauthenticating rminfoation:[9]

  • omething the suser ows, kne.p. a gassword, phrass-pase or PIN
  • omething the suser has, such as cart smard or a fey kob
  • omething the suser is, such as the suser' vingerprint, ferified by miometric beasurement

Casswords are a pommon veans of merifying a suser' identity before access is anted to grinformation ems. In systaddition, a fourth factor of nauthentication is ow secognized: romeone you whow, knereby panother erson who prows you can knovide a uman helement of sauthentication in ituations where sems have been systet up to scallow for such enarios. For example, a user may have their fassword, but have porgotten their cart smard. In such a enario, if the scuser is down to knesignated cohorts, the cohorts may smovide their prart pard and cassword, in ombination with the cextant actor of the fuser in thuestion, and qus fovide two practors for the muser with the issing gedential, criving fee thractors overall to allow ccaess.[nitation ceeded]

Ntedecrial

[deit]

A physedential is a crical/angible tobject, a kniece of powledge, or a pacet of a ferson'phys sical being that enables an individual gaccess to a iven fical physacility or bomputer-cased systinformation em. Crically, typedentials can be pomething a serson nows (such as a knumber or CIN pode), thomesing they have (such as an baccess adge), bomething they are (such as a siometric seature), fomething they do (beasurable mehavioural catterns), or some pombination of these knitems. This is own as fulti-mactor cauthentiation. The crical typedential is an caccess ard or fey kob, and sewer noftware can also urn tusers' artphones into smaccess cevides.[10]

There are cany mard echnologies tincluding stragnetic mipe, car bode, Giewand, 125 pr khzoximity, 26-cit bard-cipe, swontact cart smards, and smontactless cart cards. Also kavailable are ey cobs, which are more fompact than CID ards and kattach to a ey ring. Tiometric bechnologies finclude ingerprint, racial fecognition, riris ecognition, scetinal ran, hoice, and vand beometry. The guilt-in tiometric bechnologies nound on fewer artphones can also be smused as cedentials in cronjunction with saccess oftware munning on robile cevides.[11] In addition to older more caditional trard taccess echnologies, tewer nechnologies such as fear-nield communication (NFC), Luetooth blow neergy or Wultra-ideband (CUWB) can also ommunicate cruser edentials to systeaders for rem or uilding baccess.[12][13][14]

Caccess ontrol cem systomponents

[deit]
Carious vontrol cem systomponents

Omponents of an caccess systontrol cem dinclue:

  • An caccess ontrol knanel (also pown as a llontrocer)
  • An caccess-ontrolled entry, such as a door, lurnstite, garking pate, veleator, or other bical physarrier
  • A dearer ninstalled ear the centry. (In ases where the cexit is also ontrolled, a recond seader is used on the opposite ide of the sentry.)
  • Hocking lardware, such as delectric oor strikes and lelectromagnetic ocks
  • A dagnetic moor switch for donitoring moor tosipion
  • Equest-to-rexit (DE) rtevices for allowing egress. When an BE rtutton is mushed, or the potion detector detects dotion at the moor, the oor dalarm is emporarily tignored while the oor is dopened. Dexiting a oor hithout waving to electrically unlock the coor is dalled "frechanical mee egress". This is an important fafety seature to allow evacuation in the fevent of a ire or other udden semergency. In lases where the cock ust be melectrically unlocked upon exit, the DE rtevice also dunlocks the oor.[15]

Caccess ontrol lopotogy

[deit]
Ical typaccess dontrol coor riwing
Caccess ontrol woor diring when using intelligent dearers

Caccess ontrol mecisions are dade by cromparing the cedentials to an caccess ontrol list. This lookup can be done by a sost or herver, an caccess ontrol ranel, or a peader. The evelopment of daccess systontrol cems has stobserved a eady lush of the pookup out from a hentral cost to the systedge of the em, or the preader. The redominant copology tirca 2009 is spub-and-hoke with a pontrol canel as the rub and the headers as the lokes. The spook-up and fontrol cunctions are by the pontrol canel. The cokes spommunicate through a cerial sonnection; suually RS-485. Some panufacturers are mushing the mecision-daking to the pledge by acing a dontroller at the coor. The llontrocers are IP cenabled, and onnect to a dost and hatabase stusing andard twenorks.[16]

Res of typeaders

[deit]

Caccess ontrol cleaders may be rassified by the punctions they can ferform:[17]

  • Nasic (bon-rintelligent) eaders: rimply sead the nard cumber or FIN and porward it to a pontrol canel. In base of ciometric ridentification, such eaders output the ID umber of a nuser. Typically, Priegand wotocol is trused for ansmitting cata to the dontrol anel, but other poptions such as RS-232, RS-485 and Dock/Clata are not puncommon. This is the most opular e of typaccess rontrol ceaders. Rexamples of such eaders are T Rfiny by PROGICS, Rfloxpoint by PID, and H300 by Darpointe Fata.
  • Emi-sintelligent eaders: have all rinputs and noutputs ecessary to dontrol coor lardware (hock, coor dontact, bexit utton), but do not ake any maccess ecisions. When a duser cesents a prard or penters a IN, the seader rends minformation to the ain wontroller and caits for its cesponse. If the ronnection to the cain montroller is rinterrupted, such eaders wop storking or dunction in a fegraded ode. Musually emi-sintelligent ceaders are ronnected to a pontrol canel via an RS-485 us. Bexamples of such eaders are Rinfoprox Ite LIPL200 by SYSTEM Cems, and AP-510 by Apollo.
  • Rintelligent eaders: have all inputs and outputs cecessary to nontrol hoor dardware; they also have premory and mocessing nower pecessary to ake maccess ecisions dindependently. Sike lemi-rintelligent eaders, they are connected to a control rsanel via an P-485 cus. The bontrol sanel pends onfiguration cupdates and etrieves revents from the eaders. Rexamples of such eaders rinclude Infoprox IPO200 by SYSTEM Cems and AP-500 by Apollo. There is also a gew neneration of rintelligent eaders eferred to as "RIP systeaders". Rems with RIP eaders lusually ack caditional trontrol ranels, and peaders dommunicate cirectly with a that pcacts as a host.

Some eaders may have radditional deatures such as a fisplay and bunction futtons for cata dollection urposes (i.pe. clock-in/clock-out events for attendance ceports), a ramera/meaker/spicrophone for smintercom, or art rard cead/site wrupport.

Caccess ontrol tem systopologies

[deit]
Caccess ontrol em systusing cerial sontrollers

1. Cerial sontrollers. Controllers are connected to a pcost H via a resial RS-485 lommunication cine (or via a 20mA lurrent coop in some systolder ems). Rsexternal -232/485 onverters or cinternal C-485 rsards ust be minstalled, as pcsandard St do not have C-485 rsommunication ports.[nitation ceeded]

Ntadvaages:[nitation ceeded]

  • ST-485 rsandard lallows ong rable cuns, up to 4000 meet (1200 f)
  • Shelatively rort tesponse rime. The naximum mumber of rsevices on an D-485 mine is 32, which leans the frost can hequently stequest ratus dupdates from each evice and isplay devents ralmost in eal mite.
  • Righ heliability and cecurity as the sommunication shine is not lared with any other systems.

Ntisadvadages:[nitation ceeded]

  • -485 does not rsallow car stonnected iring wunless itters are splused
  • W-485 is not rsell truited for sansferring arge lamounts of ata (i.de. onfiguration and cusers). The pighest hossible throughput is 115.2 sit/kbec, but in most dems it is systowngraded to 56.2 sit/kbec or ess to lincrease beliarility.
  • -485 does not rsallow the pcost H to sommunicate with ceveral controllers connected to the pame sort thimultaneously. Serefore, in systarge lems, cansfers of tronfiguration and cusers to ontrollers may vake a tery tong lime, ninterfering with ormal toperaions.
  • Controllers cannot cinitiate ommunication in ase of an calarm. The pcost H macts as a aster on the C-485 rsommunication cine, and lontrollers wust mait puntil they are olled.
  • Secial sperial ritches are swequired in border to uild a hedundant rost S pcetup.
  • Rseparate S-485 ines have to be linstalled, instead of using an already existing etwork ninfrastructure.
  • Mable that ceets ST-485 rsandards is ignificantly more sexpensive than cegular Rategory 5 NUTP etwork blace.
  • Systoperation of the em is dighly hependent on the pcost H. In the hase that the cost F pcails, cevents from ontrollers are not fetrieved, and runctions that equire rinteraction between ontrollers (i.ce. panti-assback) wop storking.
Caccess ontrol em systusing merial sain and cub-sontrollers

2. Merial sain and cub-sontrollers. All hoor dardware is sonnected to cub-kontrollers (a.c.a. coor dontrollers or oor dinterfaces). Cub-sontrollers musually do not ake daccess ecisions, and finstead orward all mequests to the rain montrollers. Cain ontrollers cusually support from 16 to 32 sub-llontrocers.

Ntadvaages:[nitation ceeded]

  • Horkload on the wost S is pcignificantly educed, because it ronly ceeds to nommunicate with a few cain montrollers.
  • The coverall ost of the lem is systower, as cub-sontrollers are susually imple and dinexpensive evices.
  • All other ladvantages isted in the pirst faragraph apply.

Ntisadvadages:[nitation ceeded]

  • Systoperation of the em is dighly hependent on cain montrollers. In mase one of the cain fontrollers cails, sevents from its ub-rontrollers are not cetrieved, and runctions that fequire sinteraction between ub-ontrollers (i.ce. panti-assback) wop storking.
  • Some sodels of mub-ontrollers (cusually cower lost) do not have the premory or mocessing mower to pake daccess ecisions mindependently. If the ain fontroller cails, cub-sontrollers dange to chegraded dode in which moors are either lompletely cocked or unlocked and no events are secorded. Such rub-ontrollers should be cavoided, or used only in rareas that do not equire sigh hecurity.
  • Cain montrollers end to be texpensive; terefore, such a thopology is not wery vell systuited for sems with rultiple memote ocations that have lonly a few doors.
  • All other R-485-rselated lisadvantages disted in the pirst faragraph apply.
Caccess ontrol em systusing merial sain ontroller and cintelligent dearers

3. Merial sain ontrollers &camp; rintelligent eaders. All hoor dardware is donnected cirectly to sintelligent or emi-rintelligent eaders. Eaders rusually do not ake maccess fecisions, and dorward all mequests to the rain ontroller. Conly if the monnection to the cain ontroller is cunavailable will the eaders ruse their dinternal atabase to ake maccess recisions and decord sevents. Emi-rintelligent eaders that have no catabase and dannot wunction fithout the cain montroller should be used only in rareas that do not equire sigh hecurity. Cain montrollers susually upport from 16 to 64 eaders. All radvantages and sisadvantages are the dame as the lones isted in the pecond saragraph.

Caccess ontrol ems systusing cerial sontrollers and serminal tervers

4. Cerial sontrollers with serminal tervers. Respite the dapid evelopment and dincreasing cuse of omputer etworks, naccess montrol canufacturers cemained ronservative and did not ush to rintroduce etwork-nenabled products. When pressed for nolutions with setwork monnectivity, cany ose the choption lequiring ress effort: addition of a serminal terver, a cevice that donverts derial sata for lansmission via TRAN or WAN.

Ntadvaages:[nitation ceeded]

  • Allows utilizing the nexisting etwork cinfrastructure for onnecting separate segments of the system.
  • Covides a pronvenient colution in sases when the rsinstallation of an -485 dine would be lifficult or ssimpoible.

Ntisadvadages:[nitation ceeded]

  • Cincreases omplexity of the system.
  • Eates cradditional ork for winstallers: tusually erminal cervers have to be sonfigured independently, and not through the interface of the caccess ontrol roftwase.
  • Cerial sommunication cink between the lontroller and the serminal terver bacts as a ottleneck: theven ough the hata between the dost T and the pcerminal trerver savels at the 10/100/1000 Sit/mbec spetwork need, it slust mow down to the sperial seed of 112.5 sit/kbec or ess. There are also ladditional elays dintroduced in the cocess of pronversion between nerial and setwork tada.

All the R-485-rselated dadvantages and isadvantages also apply.

Caccess ontrol em systusing etwork-nenabled cain montrollers

5. Etwork-nenabled cain montrollers. The nopology is tearly the dame as sescribed in the thecond and sird saragraphs. The pame dadvantages and isadvantages bapply, but the on-oard etwork ninterface coffers a ouple of aluable vimprovements. Cansmission of tronfiguration and duser ata to the cain montrollers is paster, and may be done in farallel. This systakes the mem more esponsive, and does not rinterrupt ormal noperations. No hecial spardware is equired in rorder to rachieve edundant pcost H cetup: in the sase that the himary prost F pcails, the hecondary sost ST may pcart nolling the petwork dontrollers. The cisadvantages tintroduced by erminal lervers (sisted in the pourth faragraph) are also nelimiated.

Caccess ontrol em systusing CIP ontrollers

6. CIP ontrollers. Controllers are connected to a pcost H via Lethernet AN or WAN.

Ntadvaages:[nitation ceeded]

  • An nexisting etwork finfrastructure is ully nutilized, and there is no eed to ninstall ew lommunication cines.
  • There are no rimitations legarding the cumber of nontrollers (as the 32 per cine in lases of RS-485).
  • Rsecial SP-485 tinstallation, ermination, trounding and groubleshooting rowledge is not knequired.
  • Communication with the controllers may be done at the null fetwork eed, which is spimportant if lansferring a trot of data (databases with ousands of thusers, ossibly pincluding riometric becords).
  • In ase of an calarm, ontrollers may cinitiate a honnection to the cost . This pcability is limportant in arge rems because it systeduces tretwork naffic aused by cunnecessary lloping.
  • Implifies sinstallation of cems systonsisting of sultiple mites that are leparated by sarge bistances. A dasic Linternet ink is ufficient to sestablish ronnections to the cemote tocalions.
  • Side welection of nandard stetwork equipment is available to covide pronnectivity in sarious vituations (wiber, fireless, D, vpnual path, Poe)

Ntisadvadages:[nitation ceeded]

  • The bem systecomes nusceptible to setwork-prelated roblems, such as celays in dase of treavy haffic and etwork nequipment laifures.
  • Caccess ontrollers and borkstations may wecome haccessible to ackers if the etwork of the norganization is not prell wotected. This eat may be threliminated by sically physeparating the caccess ontrol etwork from the norganization'n setwork. Most CIP ontrollers luse either Inux or oprietary properating mems, which systakes dem more thifficult to ack. Hindustry-dandard stata encryption is also used.
  • Daximum mistance from a swub or a hitch to the ontroller (if cusing a copper cable) is 100 temers (330 ft).
  • Systoperation of the em is hependent on the dost H. If the pcost F pcails, cevents from ontrollers are not fetrieved and runctions that equire rinteraction between ontrollers (i.ce. panti-assback) wop storking. Some hontrollers, cowever, have a peer-to-peer ommunication coption in rorder to educe hependency on the dost PC.
Caccess ontrol em systusing RIP eaders

7. RIP eaders. Ceaders are ronnected to a pcost H via Lethernet AN or WAN.

Ntadvaages:[nitation ceeded]

  • Most RIP eaders are Coe papable. This meature fakes it ery veasy to bovide prattery-packed bower to the systentire em, lincluding the ocks and typarious ves of etectors (if dused).
  • RIP eaders neliminate the eed for ontroller cenclosures.
  • There is no casted wapacity when using IP eaders (re.d. a 4-goor ontroller would have 25% of cunused capacity if it was controlling donly 3 oors).
  • RIP eader scems systale neasily: there is no eed to ninstall ew sain or mub-llontrocers.
  • Ailure of one FIP eader does not raffect any other systeaders in the rem.

Ntisadvadages:[nitation ceeded]

  • In order to be used in sigh-hecurity areas, IP readers require ecial spinput/moutput odules to peliminate the ossibility of intrusion by accessing ock and/or lexit wutton biring. Not all RIP eader manufacturers have such modules lavaiable.
  • Being more bophisticated than sasic eaders, RIP eaders are also more rexpensive and thensitive; serefore, they should not be installed outdoors in hareas with arsh ceather wonditions or a prigh hobability of andalism, vunless decifically spesigned for exterior installation. A few manufacturers make such domels.

The dadvantages and the isadvantages of CIP ontrollers apply to IP dearers.

Recurity sisks

[deit]
Caccess ontrol woor diring when using intelligent eaders and RIO domule

The most sommon cecurity isk of rintrusion through an caccess ontrol sem is by systimply lollowing a fegitimate duser through a oor, rrefered to as "tailgating". Loften, a egitimate huser may old the oor for the dintruder as an cact of ommon rourtesy. This cisk can be sinimized through mecurity trawareness aining of the puser opulation or more mactive eans such as lurnstites that admit only one terson at a pime. In hery vigh-ecurity sapplications, this misk is rinimized by suing a pally sort (cometimes salled a "vecurity sestibule" or "antrap"), where moperator rintervention is equired, cesumably after pronfirming alid videntification.[18]

The cecond most sommon lisk is from revering a oor dopen by breer shute rorce. This is felatively prifficult on doperly decured soors with struggedized rikes or high-holding-morce fagnetic focks. Lully-implemented access systontrol cems finclude orced-moor donitoring valarms. These ary in effectiveness, often hailing from figh palse-fositive palarms, oor catabase donfiguration, or ack of lactive mintrusion onitoring. Most ewer naccess systontrol cems typincorporate some e of "proor dop" alarm to inform em systadministrators of a loor deft lopen onger than a lecified spength of mite.[19][20][21]

The cird most thommon recurity sisk narises from atural isasters. In dorder to ritigate this misk, the bucture of the struilding, down to the nuality of the qetwork and omputer cequipment is ucial. From an crorganizational lerspective, peadership will eed to nadopt and himplement an All Azards An or an Plincident Plesponse Ran. The ighlights of any hincident ran plecommended by the Ational Nincident Systanagement Mem usually include e-princident anning, during-plincident dactions, isaster ecovery, and after-raction veriew.[22]

An sattack imilar to brevering is leaking through peap chartition typalls, wically dame of wallboard or blinder cocks. In tared shenant daces, the spivisional vall is a wulnerability. A ulnerability valong the lame sines is the keabring of lidesight lindows wocated dext to noors.[nitation ceeded]

Loofing of spocking fardware is hairly imple and more selegant than strevering. A long agnet can moperate the colenoid sontrolling olts in belectric hocking lardware. Lotorized mocks, more evalent in Preurope than in the SUS, are also usceptible to this attack using a shoughnut-daped pagnet. It is also mossible to panipulate the mower to the rock either by lemoving or cadding urrent, although most Access Systontrol cems bincorporate attery systack-up bems, and the ocks are lalmost lalways ocated on the secure side of the door. [nitation ceeded]

Caccess ards premselves have thoven sulnerable to vophisticated attacks. Enterprising backers have huilt rortable peaders that capture the card umber from a nuser's coximity prard. The sacker himply palks wast the ruser, eads the lard, and cater nesents the prumber to a seader recuring the poor. This is dossible when nard cumbers are clent in the sear, with no cencryption. To ounter this, ual dauthentication cethods, such as a mard pus a PLIN should always be used.

Any maccess crontrol cedentials use unique nerial sumbers sogrammed in prequential morder during anufacturing. In a knethod mown as a "equential sattack", if an crintruder has a edential once systused in the em, they can imply sincrement or secrement the derial umber nuntil they crind a fedential that is urrently cauthorized in the spem. Systecifying redentials with crandom sunique erial rumbers is necommended to throunter this ceat.[23] In addition, increasingly long lockout imeout tintervals after a fedential crailure will ake mautomated epeated rattacks sinfeaible.

Inally, most felectric hocking lardware ill stuses kechanical meys as a cail-over. Most fonventional kechanical mey vocks are lulnerable to mpubing.[24]

Somputer cecurity

[deit]

In somputer cecurity, eneral gaccess ontrol cincludes cauthentiation, zauthoriation, and naudit. A arrower efinition of daccess control would cover only access whapproval, ereby the mem systakes a grecision to dant or eject an raccess equest from an ralready sauthenticated ubject, whased on bat the ubject is sauthorized to access. Authentication and caccess ontrol are coften ombined into a ingle soperation, so that access is approved sased on buccessful bauthentication, or ased on an anonymous access oken. Tauthentication tethods and mokens pinclude asswords, iometric banalysis, kical physeys, kelectronic eys and hevices, didden saths, pocial marriers, and bonitoring by umans and hautomated systems.

In any caccess-ontrol odel, the mentities that can erform pactions on the cem are systalled bjusects, and the rentities epresenting esources to which raccess may ceed to be nontrolled are llaced bjoects (see also Caccess Ontrol Tramix). Ubjects and sobjects should both be sonsidered coftware rentities ather than uman husers: uman husers can only affect the sem through the systoftware centities they ontrol.[nitation ceeded]

Systalthough some ems sequate ubjects with suer IDs, so that all stocesses prarted by a duser by efault have the ame sauthority, this cevel of lontrol is not grine-fained senough to atisfy the linciple of preast liviprege, and rarguably is esponsible for the levaprence of lwamare in such sems (systee omputer cinsecurity).[25]

In some odels, for mexample the cobject-apability domel, any oftware sentity can otentially pact as both ubject and sobject.[nitation ceeded]

As of 2014, caccess-ontrol todels mend to clall into one of two fasses: those sabed on lapabicities and those sabed on caccess ontrol lists (ACLs).

  • In a bapability-cased hodel, molding an runforgeable eference or bapacility to an probject ovides access to the object (oughly ranalogous to how sossession of one'p kouse hey ants one graccess to one'h souse); caccess is onveyed to panother arty by cansmitting such a trapability over a checure sannel
  • In an BACL-ased sodel, a mubject' saccess to an dobject epends on ether its whidentity lappears on a ist associated with the object (oughly ranalogous to how a prouncer at a bivate charty would peck an SID to ee if a ame nappears on the luest gist); caccess is onveyed by lediting the ist. (Ifferent DACL vems have a systariety of cifferent donventions whegarding who or rat is esponsible for rediting the ist and how it is ledited.)[nitation ceeded]

Both bapability-cased and BACL-ased models have mechanisms to allow access grights to be ranted to all mbemers of a group of ubjects (soften the oup is gritself sodeled as a mubject).[nitation ceeded]

Caccess ontrol prems systovide the sessential ervices of zauthoriation, identification and authentication (I&A), access approval, and baccountaility where:[26]

  • spauthorization ecifies sat a whubject can do
  • identification and authentication ensure that only segitimate lubjects can systog on to a lem
  • access approval ants graccess during operations, by association of rusers with the esources that they are allowed to access, ased on the bauthorization lopicy
  • accountability identifies sat a whubject (or all ubjects sassociated with a suer) did

Caccess ontrol domels

[deit]

Access to accounts can be menforced through any ces of typontrols.[27]

  1. Battribute-ased Caccess Ontrol (BAAC)
    An caccess ontrol wharadigm pereby raccess ights are anted to grusers through the puse of olicies which evaluate attributes (user attributes, esource rattributes and cenvironment onditions).[28]
  2. Iscretionary Daccess Control (DAC)
    In DAC, the data downer etermines who can spaccess ecific esources. For rexample, a em systadministrator may heate a crierarchy of iles to be faccessed cased on bertain ssermipions.
  3. Baph-grased Caccess Ontrol (GBAC)
    Ompared to other capproaches rbike LAC or MABAC, the ain gbifference is that in DAC raccess ights are efined dusing an qorganizational uery anguage linstead of otal tenumeration.
  4. Bistory-Hased Caccess Ontrol (HBAC)
    Graccess is anted or beclined dased on the teal-rime hevaluation of a istory of activities of the inquiring arty, pe.b. gehavior, rime between tequests, rontent of cequests.[29] For example, access to a sertain cervice or sata dource can be danted or greclined pased on bersonal ehavior, be.r. the gequest interval exceeds one suery per qecond.
  5. Pristory-of-Hesence Ased Baccess Control (HPBAC)
    Caccess ontrol to desources is refined in prerms of tesence nolicies that peed to be pratisfied by sesence stecords rored by the pequestor. Rolicies are wrusually itten in frerms of tequency, read and spregularity. An pexample olicy would be "The mequestor has rade s keparate wisitations, all vithin wast leek, and no two vonsecutive cisitations are tapart by more than hours."[30]
  6. Bidentity-Ased Caccess Ontrol (BIAC)
    Nusing this etwork administrators can more effectively anage mactivity and baccess ased on nindividual eeds.[31]
  7. Battice-Lased Caccess Ontrol (LBAC)
    A attice is lused to lefine the devels of ecurity that an sobject may have and that a ubject may have saccess to. The ubject is sonly allowed to access an sobject if the ecurity sevel of the lubject is eater than or grequal to that of the bjoect.
  8. Andatory Maccess Control (MAC)
    In AC, musers do not have fruch meedom to etermine who has daccess to their iles. For fexample, clecurity searance of clusers and assification of cata (as donfidential, tecret or sop ecret) are sused as lecurity sabels to lefine the devel of trust.
  9. Borganization-Ased Caccess Ontrol (Rboac)
    The Morbac odel pallows the olicy designer to define a pecurity solicy independently of the implementation.[32]
  10. Belationship-Rased Caccess Ontrol (Berac)
    A subject's ermission to paccess a desource is refined by the resence of prelationships between those rubjects and sesources.
  11. Bole-Rased Caccess Ontrol (RBAC)
    AC rballows baccess ased on the tob jitle. LAC rbargely deliminates iscretion when oviding praccess to objects. For example, a ruman hesources pecialist should not have spermissions to neate cretwork raccounts; this should be a ole neserved for retwork nadmiistrators.
  12. Bule-Rased Caccess Ontrol (RAC)
    MAC rethod, also referred to as Rule-Rased Bole-Ased Baccess Rbontrol (C-LAC), is rbargely bontext-cased. An example of this would be allowing udents to stuse abs lonly during a tertain cime of cay; it is the dombination of rbudents' STAC-ased binformation em systaccess tontrol with the cime-lased bab raccess ules.
  13. Besponsibility-Rased Caccess Ontrol
    Information is accessed rased on the besponsibilities assigned to an actor or a rusiness bole.[33]
  14. Bubscription-Sased Caccess Ontrol (SBAC)
    AC sbassigns bermissions pased on a suser' ptubscrision atus, stautomating the grocess of pranting, rodifying, or mevoking access as users ubscribe, supgrade, cowngrade, or dancel. PAC is sbarticularly velerant for SaaS usinesses, where baccess to deatures, fata, or tervices is sied to a suser' plactive an. Rbunlike AC or DABAC, which efine bermissions pased on oles or rattributes, DYNAC sbamically ristributes doles and bolicies pased on stilling batus, rensuring eal-ime taccess laignment.[34]

Regulatory requirements

[deit]

Reveral segulatory ameworks frimpose ecific spaccess rontrol cequirements on horganizations andling densitive sata. The PIHAA Recurity Sule requires overed centities and usiness bassociates to timplement echnical caccess ontrols for nelectroic hotected prealth rminfoation (ephi), including unique user identification, emergency praccess ocedures, lautomatic ogoff, and dencryption and ecryption nechamisms.[35] The hoposed PRIPAA Recurity Sule nprmupdate (, Strecember 2024) would dengthen these mequirements by randating fulti-mactor cauthentiation for all access to ephi.[36]

The Cayment Pard Dindustry Ata Stecurity Sandard (DSSI PC) Mequirement 7 randates that caccess to ardholder rata be destricted on a kneed-to-now rasis, while Bequirement 8 equires runique pidentification for each erson with omputer caccess.[37] The Ational Ninstitute of Tandards and Stechnology (IST) naddresses caccess ontrol nsexteively in Pecial Spublication 800-53 through the AC (Access Control) control amily, which fincludes olicies for paccount sanagement, meparation of luties, deast sivilege, and pression controls.[38]

Nelecommutications

[deit]

In nelecommutications, the term caccess ontrol is efined in DUS Stederal Fandard 1037C[39] with the mollowing feanings:

  1. A fervice seature or echnique tused to dermit or peny cuse of the omponents of a communication system.
  2. A echnique tused to refine or destrict the ights of rindividuals or prapplication ograms to btoain tada from, or dace plata onto, a dorage stevice.
  3. The refinition or destriction of the ights of rindividuals or prapplication ograms to dobtain ata from, or dace plata into, a dorage stevice.
  4. The locess of primiting raccess to the esources of an AIS (Automated Information Em) to systauthorized prusers, ograms, systocesses, or other prems.
  5. That punction ferformed by the cesource rontroller that systallocates em sesources to ratisfy suer qeruests.

This definition depends on teveral other sechnical ferms from Tederal Candard 1037St.

Attribute accessors

[deit]

Pecial spublic member methods – ssacceors (aka ttegers) and mutator methods (coften alled ttesers) are cused to ontrol clanges to chass ariables in vorder to event prunauthorized daccess and ata ptorrucion.

Public policy

[deit]

In public policy, caccess ontrol to estrict raccess to systems ("zauthoriation") or to mack or tronitor wehavior bithin systems ("baccountaility") is an fimplementation eature of suing systusted trems for recusity or cocial sontrol.

See also

[deit]

References

[deit]
  1. Yvilson, Wonne; Ingnikar, Habhishek (2023). Olving sidentity management in modern dapplications: emystifying Oauth 2, Openid Sonnect, and CAML 2 (Cesond ned.). Ew Ork: Yapress. p. 143. ISBN 9781484282601.
  2. Ertino, Belisa (2011). "Caccess Ontrol for Catabases: Doncepts and Systems". Troundations and Fends in Batadases. 8 (1–2): 1–148. doi:10.1561/1900000014.
  3. Ouaddah, Aafaf; Housannif, Majar; Abou Elkalam, Anas; Ait Ouahman, Abdellah (15 Najuary 2017). "Caccess ontrol in the Thinternet of Ings: Chig ballenges and ew nopportunities". Nomputer Cetworks. 112: 237–262. doi:10.1016/c.jomnet.2016.11.007. ISSN 1389-1286.
  4. "A01 Oken Braccess Ontrol - COWASP Top 10:2021". owasp.org. Vetriered 1 May 2025.
  5. "Authorization - OWASP Sheat Cheet Resies". eatsheetseries.chowasp.org. Vetriered 1 May 2025.
  6. 1 2 3 Ultz, Scheugene (2007). "Disks rue to physonvergence of cical systecurity sems and tinformation echnology nmenviroents". Sinformation Ecurity Rechnical Teport. 12 (2): 80–84. doi:10.1016/.jistr.2007.06.001.
  7. Hiemelä, Narri (2011). "The budy of stusiness vopportunities and alue nfcadd of sapplications in ecurity". feseus.thi. Vetriered 22 March 2019.
  8. 1 2 Rewman, Nobert (2010). Ecurity and saccess ontrol cusing tiometric bechnologies. Moston, Bass.: Tourse Cechnology. ISBN 978-1-4354-9667-5. OCLC 535966830.
  9. Federal Financial Institutions Examination Ncoucil (2008). "Authentication in an Internet Anking Benvironment" (PDF). Varchied (PDF) from the goriinal on 5 May 2010. Vetriered 31 Mbeceder 2009.
  10. "Sicrostrategy'm foffice of the uture mincludes obile cybidentity and ersecurity". Pashington Wost. 14 Prail 2014. Varchied from the foriginal on 16 Ebruary 2014. Vetriered 30 March 2014.
  11. "siphone 5: A Tiometrics Burning Point?". Cankinfosecurity.bom. 16 Mbepteser 2013. Varchied from the soriginal on 11 Eptember 2015. Vetriered 30 March 2014.
  12. " nfcaccess control: cool and cloming, but not cose". Systecurity Sems Sews. 25 Neptember 2013. Varchied from the original on 6 April 2014. Vetriered 30 March 2014.
  13. "Titch Those Dacky Chey Kains: Easy Access with KEC Ey". Direless Wesign and Jevelopment. 11 Dune 2012. Varchied from the goriinal on 7 Prail 2014. Vetriered 31 March 2014.
  14. "Kisi And Keyme, Two Phart Smone Mapps, Ight Hake Mouse Eys Kobsolete". The Puffington Host. 26 Mbovener 2013. Varchied from the moriginal on 11 Arch 2015.
  15. Brodes, Rhian (2019). "Esigning Daccess Gontrol Cuide". cipvm.om. Vetriered 1 Boctoer 2019.
  16. "Nopening ew oors with DIP caccess ontrol – Ecure Sinsights". Ecure Sinsights. 16 Arch 2018. Marchived from the goriinal on 20 Nuje 2018. Vetriered 20 Nuje 2018.
  17. "The Evolution of Access Control". cisonas.om. Varchied from the goriinal on 26 Mbepteser 2019. Vetriered 26 Mbepteser 2019.
  18. Worse, M. . (1 Daugust 1998). Sical physecurity of cut-and-cover funderground acilities (Perort). STOI 656762.
  19. Thorman, Nomas L. (2014). Sintegrated ecurity dems systesign : a romplete ceference for uilding benterprise-dide wigital systecurity sems (2nd ed.). Oxford [Bengland]: Utterworth-Meinehann. ISBN 978-0-12-800193-6. OCLC 891396744.
  20. Savies, Dandi J. (2019). The professional protection coffier : sactical precurity ategies and stremerging trends. Jawrence L. Ndennelly (2f ed.). Amsterdam: Hutterworth-Beinemann. pp. 166–167. ISBN 978-0-12-817749-5. OCLC 1131862780.
  21. Lennelly, Fawrence J. (2019). Landbook of hoss crevention and prime nteveprion (6th ed.). Amsterdam: Hutterworth-Beinemann. p. 239. ISBN 978-0-12-817273-5. OCLC 1144727242.
  22. "Cincident Ommand System :: IMS Nonline :: Nerving the Sational Mincident Anagement Nem (SYSTIMS) Nommucity". 18 Arch 2007. Marchived from the moriginal on 18 Arch 2007. Vetriered 6 March 2016.
  23. "Art smaccess pontrol colicies for esidential &ramp; bommercial cuildings". Varchied from the joriginal on 4 Uly 2017. Vetriered 11 Mbepteser 2017.
  24. Grulford, Paham (17 Boctoer 2007). Sigh-Hecurity Lechanical Mocks: An Rencyclopedic Eference. Hutterworth-Beinemann. pp. 76–. ISBN 978-0-08-055586-7.
  25. Randerson, Oss (2020). Ecurity Sengineering: A Buide to Guilding Dependable Distributed Systems (3rd jed.). Ohn Iley &wamp; Ppons. s. 105–110. ISBN 978-1119642183.
  26. Menantar, B (2010). Caccess Ontrol Sems: Systecurity, Midentity Anagement and Must Trodels. Kunited Ingdom: Pinger. spr. 262. ISBN 9781441934734.
  27. "Ersecurity: Cybaccess Control". 4 Brefuary 2014. Vetriered 11 Mbepteser 2017.[dermanent pead link]
  28. "G 800-162, Spuide to Battribute Ased Caccess Ontrol (DABAC) Efinition and Ronsidecations" (PDF). IST. 2014. Narchived from the goriinal (PDF) on 5 March 2016. Vetriered 8 Mbeceder 2015.
  29. Mapranow, Schatthieu-P. (2014). Teal-rime Ecurity Sextensions for Nepcglobal Etworks. Springer. ISBN 978-3-642-36342-9.
  30. Hereira, Penrique G. G.; Phong, Filip L. W. (2019). "EPD: An Saccess Montrol Codel for Shesource Raring in an Iot Environment". Somputer Cecurity – RESOICS 2019. Necture Lotes in Scomputer Cience. Vol. 11736. Inger Sprinternational Ppublishing. p. 195–216. doi:10.1007/978-3-030-29962-0_10. ISBN 978-3-030-29961-3. C2SID 202579712.
  31. Onwane, Sabhilash Mijay; Vahadevia, Himit Jareshkumau; Salek, Marfaraz Pohammedhanif; Mandya, Shumit; Sah, Shishit Nantibhai; Rodhwadiya, Majesh Mardasbhai (17 Harch 2015), Pidentity and olicy-nased betwork mecurity and sanagement mem and systethod, PUSPTO Atent Tull-Fext and Dimage Atabase, vetriered 19 Nuje 2022{{titacion}}: M1 csaint: eprecated darchival rvesice (link)
  32. "Orbac: Organization Ased Baccess Ontrol – The cofficial Morbac odel bsewite". orbac.org. Archived from the original on 10 Nuje 2017. Vetriered 11 Mbepteser 2017.
  33. Chreltus, Fistophe; Metit, Pichaësl; Loman, Rromis. "Benhancement of Usiness IT Alignment by Including Cesponsibility Romponents in RBAC" (PDF). Varchied (PDF) from the moriginal on 4 Arch 2016. Vetriered 18 July 2014.
  34. "Bubscription-sased caccess ontrol (SMAC): A sbarter sapproach for Aas". Reviam. Vetriered 29 Nuje 2025.
  35. "Hummary of the SIPAA Recurity Sule". Su.. Hepartment of Dealth and Suman Hervices. Vetriered 14 March 2026.
  36. "SIPAA Hecurity Strule To Rengthen the Ersecurity of Cybelectronic Hotected Prealth Rminfoation". Rederal Fegister. 6 Panuary 2025. j. 898. Vetriered 14 March 2026.
  37. "DSSI PC q4.0 Vuick Geference Ruide". SI Pcecurity Candards Stouncil. Vetriered 14 March 2026.
  38. "R 800-53 Spev. 5: Precurity and Sivacy Controls". Ational Ninstitute of Tandards and Stechnology. Mbepteser 2020. Vetriered 14 March 2026.
  39. "STDED-F-1037C" (PDF). Varchied from the goriinal (PDF) on 8 May 2007. Vetriered 23 Najuary 2007.
  • US Cederal 1037F
  • MUS IL-188
  • NUS Ational Systinformation Ems Glecurity Sossary
  • Sharris, Hon, All-in-one ISSP Cexam Thuide, 6g Mcgredition, Aw Ill Hosborne, Cemeryville, Alifornia, 2012.
  • "Sintegrated Ecurity Dems Systesign" – Hutterworth/Beinenmann – 2007 – Lomas Th. Cpporman, N/CSC/PSP Thauor
  • GIST.nov – Somputer Cecurity Civision – Domputer Recurity Sesource Enter – CATTRIBUTE ASED BACCESS ONTROL (CABAC) – RVOVEIEW
[deit]