Policy analysis for administrative role based access control without separate administration

被引:3
|
作者
Yang, Ping [1 ]
Gofman, Mikhail I. [2 ]
Stoller, Scott D. [3 ]
Yang, Zijiang [4 ]
机构
[1] SUNY Binghamton, Dept Comp Sci, Binghamton, NY 13902 USA
[2] Calif State Univ Fullerton, Dept Comp Sci, Fullerton, CA 92634 USA
[3] SUNY Stony Brook, Dept Comp Sci, Stony Brook, NY 11794 USA
[4] Western Michigan Univ, Dept Comp Sci, Kalamazoo, MI 49008 USA
基金
美国国家科学基金会;
关键词
Administrative role-based access control; policy analysis;
D O I
10.3233/JCS-140511
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Role based access control (RBAC) is a widely used approach to access control with well-known advantages in managing authorization policies. This paper considers user-role reachability analysis of administrative role based access control (ARBAC), which defines administrative roles and specifies how members of each administrative role can change the RBAC policy. Most existing works on user-role reachability analysis assume the separate administration restriction in ARBAC policies. While this restriction greatly simplifies the user-role reachability analysis, it also limits the expressiveness and applicability of ARBAC. In this paper, we consider analysis of ARBAC without the separate administration restriction and present new techniques to reduce the number of ARBAC rules and users considered during analysis. We also present parallel algorithms that speed up the analysis on multi-core systems. The experimental results show that our techniques significantly reduce the analysis time, making it practical to analyze ARBAC without separate administration.
引用
收藏
页码:1 / 29
页数:29
相关论文
共 50 条
  • [1] Policy Analysis for Administrative Role Based Access Control without Separate Administration
    Yang, Ping
    Gofman, Mikhail
    Yang, Zijiang
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXVII, 2013, 7964 : 49 - 64
  • [2] Efficient Policy Analysis for Administrative Role Based Access Control
    Stoller, Scott D.
    Yang, Ping
    Ramakrishnan, C. R.
    Gofman, Mikhail I.
    CCS'07: PROCEEDINGS OF THE 14TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2007, : 445 - +
  • [3] Policy analysis for Administrative Role-Based Access Control
    Sasturkar, Amit
    Yang, Ping
    Stoller, Scott D.
    Ramakrishnan, C. R.
    THEORETICAL COMPUTER SCIENCE, 2011, 412 (44) : 6208 - 6234
  • [4] A Role-Based Administrative Model for Administration of Heterogeneous Access Control Policies and its Security Analysis
    Singh, Mahendra Pratap
    Sural, Shamik
    Vaidya, Jaideep
    Atluri, Vijayalakshmi
    INFORMATION SYSTEMS FRONTIERS, 2021, 26 (6) : 2255 - 2272
  • [5] Symbolic Reachability Analysis for Parameterized Administrative Role Based Access Control
    Stoller, Scott D.
    Yang, Ping
    Gofman, Mikhail
    Ramakrishnan, C. R.
    SACMAT'09: PROCEEDINGS OF THE 14TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2009, : 165 - 174
  • [6] Incremental Analysis of Evolving Administrative Role Based Access Control Policies
    Ranise, Silvio
    Anh Truong
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXVIII, 2014, 8566 : 260 - 275
  • [7] User-Role Reachability Analysis of Evolving Administrative Role Based Access Control
    Gofman, Mikhail I.
    Luo, Ruiqi
    Yang, Ping
    COMPUTER SECURITY-ESORICS 2010, 2010, 6345 : 455 - 471
  • [8] Symbolic reachability analysis for parameterized administrative role-based access control
    Stoller, Scott D.
    Yang, Ping
    Gofman, Mikhail I.
    Ramakrishnan, C. R.
    COMPUTERS & SECURITY, 2011, 30 (2-3) : 148 - 164
  • [9] Scalable and Precise Automated Analysis of Administrative Temporal Role-Based Access Control
    Ranise, Silvio
    Truong, Anh
    Armando, Alessandro
    PROCEEDINGS OF THE 19TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES (SACMAT'14), 2014, : 103 - 114
  • [10] Security Analysis of Administrative Role-Based Access Control Policies with Contextual Information
    Khai Kim Quoc Dinh
    Tuan Duc Tran
    Anh Truong
    FUTURE DATA AND SECURITY ENGINEERING, 2017, 10646 : 243 - 261