Policy analysis for administrative role based access control without separate administration.
Saved in:
| Title: | Policy analysis for administrative role based access control without separate administration. |
|---|---|
| Authors: | Yang, Ping1, Gofman, Mikhail I.2, Stoller, Scott D.3, Yang, Zijiang4 |
| Source: | Journal of Computer Security. Jan2015, Vol. 23 Issue 1, p1-29. 29p. |
| Subjects: | Access control, Computer security research, Parallel algorithms, Algorithms, Computer systems |
| Abstract: | Role based access control (RBAC) is a widely used approach to access control with well-known advantages in managing authorization policies. This paper considers user-role reachability analysis of administrative role based access control (ARBAC), which defines administrative roles and specifies how members of each administrative role can change the RBAC policy. Most existing works on user-role reachability analysis assume the separate administration restriction in ARBAC policies. While this restriction greatly simplifies the user-role reachability analysis, it also limits the expressiveness and applicability of ARBAC. In this paper, we consider analysis of ARBAC without the separate administration restriction and present new techniques to reduce the number of ARBAC rules and users considered during analysis. We also present parallel algorithms that speed up the analysis on multi-core systems. The experimental results show that our techniques significantly reduce the analysis time, making it practical to analyze ARBAC without separate administration. [ABSTRACT FROM AUTHOR] |
| Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Engineering Source |
| FullText | Links: – Type: pdflink Text: Availability: 0 |
|---|---|
| Header | DbId: egs DbLabel: Engineering Source An: 101610147 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Policy analysis for administrative role based access control without separate administration. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Yang%2C+Ping%22">Yang, Ping</searchLink><relatesTo>1</relatesTo><br /><searchLink fieldCode="AR" term="%22Gofman%2C+Mikhail+I%2E%22">Gofman, Mikhail I.</searchLink><relatesTo>2</relatesTo><br /><searchLink fieldCode="AR" term="%22Stoller%2C+Scott+D%2E%22">Stoller, Scott D.</searchLink><relatesTo>3</relatesTo><br /><searchLink fieldCode="AR" term="%22Yang%2C+Zijiang%22">Yang, Zijiang</searchLink><relatesTo>4</relatesTo> – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="JN" term="%22Journal+of+Computer+Security%22">Journal of Computer Security</searchLink>. Jan2015, Vol. 23 Issue 1, p1-29. 29p. – Name: Subject Label: Subjects Group: Su Data: <searchLink fieldCode="DE" term="%22Access+control%22">Access control</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security+research%22">Computer security research</searchLink><br /><searchLink fieldCode="DE" term="%22Parallel+algorithms%22">Parallel algorithms</searchLink><br /><searchLink fieldCode="DE" term="%22Algorithms%22">Algorithms</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+systems%22">Computer systems</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: Role based access control (RBAC) is a widely used approach to access control with well-known advantages in managing authorization policies. This paper considers user-role reachability analysis of administrative role based access control (ARBAC), which defines administrative roles and specifies how members of each administrative role can change the RBAC policy. Most existing works on user-role reachability analysis assume the separate administration restriction in ARBAC policies. While this restriction greatly simplifies the user-role reachability analysis, it also limits the expressiveness and applicability of ARBAC. In this paper, we consider analysis of ARBAC without the separate administration restriction and present new techniques to reduce the number of ARBAC rules and users considered during analysis. We also present parallel algorithms that speed up the analysis on multi-core systems. The experimental results show that our techniques significantly reduce the analysis time, making it practical to analyze ARBAC without separate administration. [ABSTRACT FROM AUTHOR] – Name: AbstractSuppliedCopyright Label: Group: Ab Data: <i>Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=101610147 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.3233/JCS-140511 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 29 StartPage: 1 Subjects: – SubjectFull: Access control Type: general – SubjectFull: Computer security research Type: general – SubjectFull: Parallel algorithms Type: general – SubjectFull: Algorithms Type: general – SubjectFull: Computer systems Type: general Titles: – TitleFull: Policy analysis for administrative role based access control without separate administration. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Yang, Ping – PersonEntity: Name: NameFull: Gofman, Mikhail I. – PersonEntity: Name: NameFull: Stoller, Scott D. – PersonEntity: Name: NameFull: Yang, Zijiang IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 01 Text: Jan2015 Type: published Y: 2015 Identifiers: – Type: issn-print Value: 0926227X Numbering: – Type: volume Value: 23 – Type: issue Value: 1 Titles: – TitleFull: Journal of Computer Security Type: main |
| ResultId | 1 |