跳到主要导航 跳到搜索 跳到主要内容

Policy analysis for administrative role based access control without separate administration

  • Ping Yang
  • , Mikhail Gofman
  • , Zijiang Yang
  • State University of New York Binghamton University
  • California State University Fullerton

科研成果: 书/报告/会议事项章节会议稿件同行评审

2 引用 (Scopus)

摘要

Access control is widely used in large systems for restricting resource access to authorized users. In particular, role based access control (RBAC) is a generalized approach to access control and is well recognized for its many advantages in managing authorization policies. This paper considers user-role reachability analysis of administrative role based access control (ARBAC), which defines administrative roles and specifies how members of each administrative role can change the RBAC policy. Most existing works on user-role reachability analysis assume the separate administration restriction in ARBAC policies. While this restriction greatly simplifies the user-role reachability analysis, it also limits the expressiveness and applicability of ARBAC. In this paper, we consider analysis of ARBAC without the separate administration restriction and present new techniques to reduce the number of ARBAC rules and users considered during analysis. We also present a number of parallel algorithms that speed up the analysis on multi-core systems. The experimental results show that our techniques significantly reduce the analysis time, making it practical to analyze ARBAC without separate administration.

源语言英语
主期刊名Data and Applications Security and Privacy XXVII - 27th Annual IFIP WG 11.3 Conference, DBSec 2013, Proceedings
49-64
页数16
DOI
出版状态已出版 - 2013
活动27th Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy, DBSec 2013 - Newark, NJ, 美国
期限: 15 7月 201317 7月 2013

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
7964 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议27th Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy, DBSec 2013
国家/地区美国
Newark, NJ
时期15/07/1317/07/13

学术指纹

探究 'Policy analysis for administrative role based access control without separate administration' 的科研主题。它们共同构成独一无二的指纹。

引用此