BEYOND ROLES AND PROFILES: A HYBRID ACCESS CONTROL MODEL FOR GRANULAR SECURITY IN SALESFORCE CRM

Authors

  • ShivaKrishna Deepak Veeravalli Intercom, USA Author

DOI:

https://doi.org/10.63519/IJCSERD_12_01_008

Keywords:

Salesforce CRM, Access Control, Hybrid Security Model, RBAC, ABAC, PBAC, Cloud Security, Field-Level Access, Identity and Access Management (IAM), Enterprise Data Protection

Abstract

In enterprise-level CRM systems such as Salesforce, data security and access control are critical due to sensitive customer information and regulatory compliance requirements. Traditional Role-Based Access Control (RBAC) and Profile-Based Security models in Salesforce offer coarse-grained control that often leads to either over-permissioned or under-permissioned users. This research proposes a Hybrid Access Control Model (HACM) combining RBAC with Attribute-Based Access Control (ABAC) and Policy-Based Access Control (PBAC) to enable granular, dynamic, and context-aware access permissions. The paper presents an architecture that overlays Salesforce's native mechanisms with a modular security engine capable of interpreting context, roles, object-level and field-level constraints. The model is validated through simulated data leakage scenarios, highlighting reductions in exposure risk and unauthorized access compared to traditional models.

References

Sandhu, R., Coyne, E. J., Feinstein, H. L., & Youman, C. E. (1996). Role-Based Access Control Models. IEEE Computer, 29(2), 38–47.

Ferraiolo, D., Kuhn, R., & Chandramouli, R. (2003). Role-Based Access Control. Artech House.

Hu, V. C., Ferraiolo, D., & Kuhn, D. R. (2013). Assessment of Access Control Systems. NIST Interagency/Internal Report, 7316.

Jin, X., Krishnan, R., & Sandhu, R. (2012). A Unified Attribute-Based Access Control Model Covering DAC, MAC and RBAC. Data and Applications Security and Privacy XXVI.

Servos, D., & Osborn, S. L. (2017). Current Research and Open Problems in Attribute-Based Access Control. ACM Computing Surveys, 49(4), 1–45.

Hu, V. C., Kuhn, D. R., & Ferraiolo, D. (2015). Attribute-Based Access Control. Computer, 48(2), 85–88.

Zhang, G., & Parashar, M. (2003). Context-Aware Dynamic Access Control for Pervasive Applications. IEEE Int. Conf. on Pervasive Computing and Communications.

Park, J., & Sandhu, R. (2004). The UCONABC Usage Control Model. ACM Transactions on Information and System Security (TISSEC), 7(1), 128–174.

Yagüe, M. I., & Maña, A. (2004). An Overview of Access Control in Distributed Systems. IEEE Software, 21(5), 38–47.

Li, N., & Tripunitara, M. V. (2006). Security Analysis in Role-Based Access Control. ACM Transactions on Information and System Security, 9(4), 391–420.

Bertino, E., Sandhu, R. (2005). Database Security—Concepts, Approaches, and Challenges. IEEE Transactions on Dependable and Secure Computing, 2(1), 2–19.

Almutairi, A., Sarfraz, M., Basalamah, S., Aref, W. G., & Ghafoor, A. (2012). A Distributed Access Control Architecture for Cloud Computing. IEEE Software, 29(2), 36–44.

Ni, Q., Bertino, E., & Lobo, J. (2010). Risk-Based Access Control Systems Using Historical Data. ACM SACMAT.

Crampton, J., & Huth, M. (2010). Towards an Access Control Metamodel for Distributed Systems. CSFW.

Takabi, H., Joshi, J. B. D., & Ahn, G. J. (2010). Security and Privacy Challenges in Cloud Computing Environments. IEEE Security & Privacy, 8(6), 24–31.

Bertino, E., & Ferrari, E. (2002). Secure and Selective Dissemination of XML Documents. ACM Transactions on Information and System Security, 5(3), 290–331.

Gollmann, D. (2011). Computer Security. John Wiley & Sons.

Chen, L. Y., et al. (2014). Access Control in Multi-Tenant Cloud Systems. ACM CCS.

Rao, J. R., Rohatgi, P., & Naccache, D. (2012). The Evolution of Identity and Access Management. IBM Journal of Research and Development, 56(6), 4–1.

Enisa. (2010). Cloud Computing Risk Assessment. European Union Agency for Cybersecurity.

Zissis, D., & Lekkas, D. (2012). Addressing Cloud Computing Security Issues. Future Generation Computer Systems, 28(3), 583–592.

Tsai, W. T., et al. (2010). Access Control in Cloud Computing Using Semantic Web Technologies. IEEE COMPSAC.

Mahmood, Z. (2011). Data Location and Security Issues in Cloud Computing. International Conference on Emerging Intelligent Data and Web Technologies.

SalesForce.com. (2019). Security Implementation Guide. Salesforce Documentation.

NIST SP 800-162. (2014). Guide to Attribute-Based Access Control (ABAC) Definition and Considerations.

Downloads

Published

2022-11-15

How to Cite

ShivaKrishna Deepak Veeravalli. (2022). BEYOND ROLES AND PROFILES: A HYBRID ACCESS CONTROL MODEL FOR GRANULAR SECURITY IN SALESFORCE CRM. International Journal of Computer Science and Engineering Research and Development (IJCSERD), 12(1), 95-111. https://doi.org/10.63519/IJCSERD_12_01_008