Policy analysis for administrative role based access control without separate administration

被引:3
|
作者
Yang, Ping [1 ]
Gofman, Mikhail I. [2 ]
Stoller, Scott D. [3 ]
Yang, Zijiang [4 ]
机构
[1] SUNY Binghamton, Dept Comp Sci, Binghamton, NY 13902 USA
[2] Calif State Univ Fullerton, Dept Comp Sci, Fullerton, CA 92634 USA
[3] SUNY Stony Brook, Dept Comp Sci, Stony Brook, NY 11794 USA
[4] Western Michigan Univ, Dept Comp Sci, Kalamazoo, MI 49008 USA
基金
美国国家科学基金会;
关键词
Administrative role-based access control; policy analysis;
D O I
10.3233/JCS-140511
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Role based access control (RBAC) is a widely used approach to access control with well-known advantages in managing authorization policies. This paper considers user-role reachability analysis of administrative role based access control (ARBAC), which defines administrative roles and specifies how members of each administrative role can change the RBAC policy. Most existing works on user-role reachability analysis assume the separate administration restriction in ARBAC policies. While this restriction greatly simplifies the user-role reachability analysis, it also limits the expressiveness and applicability of ARBAC. In this paper, we consider analysis of ARBAC without the separate administration restriction and present new techniques to reduce the number of ARBAC rules and users considered during analysis. We also present parallel algorithms that speed up the analysis on multi-core systems. The experimental results show that our techniques significantly reduce the analysis time, making it practical to analyze ARBAC without separate administration.
引用
收藏
页码:1 / 29
页数:29
相关论文
共 50 条
  • [21] Improvement of a multi-role-based access control policy
    Shen, VRL
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2000, E83A (07) : 1483 - 1485
  • [22] Policy storage for role-based access control systems
    Belokosztolszki, A
    Eyers, DM
    Wang, W
    Moody, K
    TWELFTH IEEE INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 2003, : 196 - 201
  • [23] ACCOUNTABILITY IN ADMINISTRATION OF PUBLIC-POLICY - ADMINISTRATIVE OVERSIGHT AND CONTROL
    DOIG, JW
    POLICY STUDIES JOURNAL, 1976, 5 (01) : 86 - 96
  • [24] Discretionary Access Control with the Administrative Role Graph Model
    Wang, He
    Osborn, Sylvia L.
    SACMAT'07: PROCEEDINGS OF THE 12TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2007, : 151 - 156
  • [25] Cree: A Performant Tool for Safety Analysis of Administrative Temporal Role-Based Access Control (ATRBAC) Policies
    Shahen, Jonathan
    Niu, Jianwei
    Tripunitara, Mahesh, V
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (05) : 2349 - 2364
  • [26] AARBAC: Attribute-Based Administration of Role-Based Access Control
    Ninglekhu, Jiwan L.
    Krishnan, Ram
    2017 IEEE 3RD INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (CIC), 2017, : 126 - 135
  • [27] Enterprise model as a basis of administration on role-based access control
    Oh, S
    Park, S
    PROCEEDINGS OF THE THIRD INTERNATIONAL SYMPOSIUM ON COOPERATIVE DATABASE SYSTEMS FOR ADVANCED APPLICATIONS, 2000, : 150 - 158
  • [28] Collaborative Administration of Role-Based Access Control in Smart Contracts
    Crass, Stefan
    Lackner, Andreas
    Begic, Nedim
    Mirhosseini, Seyed Amid Moeinzadeh
    Kirchmayr, Nicolas
    2022 4TH CONFERENCE ON BLOCKCHAIN RESEARCH & APPLICATIONS FOR INNOVATIVE NETWORKS AND SERVICES (BRAINS), 2022, : 87 - 94
  • [29] Uni-ARBAC: A Unified Administrative Model for Role-Based Access Control
    Biswas, Prosunjit
    Sandhu, Ravi
    Krishnan, Ram
    INFORMATION SECURITY, (ISC 2016), 2016, 9866 : 218 - 230
  • [30] THE EVALUATION AND COMPARATIVE ANALYSIS OF ROLE BASED ACCESS CONTROL AND ATTRIBUTE BASED ACCESS CONTROL MODEL
    Aftab, Muhammad Umar
    Qin, Zhiguang
    Zakria
    Ali, Safeer
    Pirah
    Khan, Jalaluddin
    2018 15TH INTERNATIONAL COMPUTER CONFERENCE ON WAVELET ACTIVE MEDIA TECHNOLOGY AND INFORMATION PROCESSING (ICCWAMTIP), 2018, : 35 - 39