Policy analysis for administrative role based access control without separate administration.

Saved in:
Bibliographic Details
Title: Policy analysis for administrative role based access control without separate administration.
Authors: Yang, Ping1, Gofman, Mikhail I.2, Stoller, Scott D.3, Yang, Zijiang4
Source: Journal of Computer Security. Jan2015, Vol. 23 Issue 1, p1-29. 29p.
Subjects: Access control, Computer security research, Parallel algorithms, Algorithms, Computer systems
Abstract: Role based access control (RBAC) is a widely used approach to access control with well-known advantages in managing authorization policies. This paper considers user-role reachability analysis of administrative role based access control (ARBAC), which defines administrative roles and specifies how members of each administrative role can change the RBAC policy. Most existing works on user-role reachability analysis assume the separate administration restriction in ARBAC policies. While this restriction greatly simplifies the user-role reachability analysis, it also limits the expressiveness and applicability of ARBAC. In this paper, we consider analysis of ARBAC without the separate administration restriction and present new techniques to reduce the number of ARBAC rules and users considered during analysis. We also present parallel algorithms that speed up the analysis on multi-core systems. The experimental results show that our techniques significantly reduce the analysis time, making it practical to analyze ARBAC without separate administration. [ABSTRACT FROM AUTHOR]
Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 101610147
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Policy analysis for administrative role based access control without separate administration.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Yang%2C+Ping%22">Yang, Ping</searchLink><relatesTo>1</relatesTo><br /><searchLink fieldCode="AR" term="%22Gofman%2C+Mikhail+I%2E%22">Gofman, Mikhail I.</searchLink><relatesTo>2</relatesTo><br /><searchLink fieldCode="AR" term="%22Stoller%2C+Scott+D%2E%22">Stoller, Scott D.</searchLink><relatesTo>3</relatesTo><br /><searchLink fieldCode="AR" term="%22Yang%2C+Zijiang%22">Yang, Zijiang</searchLink><relatesTo>4</relatesTo>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Journal+of+Computer+Security%22">Journal of Computer Security</searchLink>. Jan2015, Vol. 23 Issue 1, p1-29. 29p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Access+control%22">Access control</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security+research%22">Computer security research</searchLink><br /><searchLink fieldCode="DE" term="%22Parallel+algorithms%22">Parallel algorithms</searchLink><br /><searchLink fieldCode="DE" term="%22Algorithms%22">Algorithms</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+systems%22">Computer systems</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Role based access control (RBAC) is a widely used approach to access control with well-known advantages in managing authorization policies. This paper considers user-role reachability analysis of administrative role based access control (ARBAC), which defines administrative roles and specifies how members of each administrative role can change the RBAC policy. Most existing works on user-role reachability analysis assume the separate administration restriction in ARBAC policies. While this restriction greatly simplifies the user-role reachability analysis, it also limits the expressiveness and applicability of ARBAC. In this paper, we consider analysis of ARBAC without the separate administration restriction and present new techniques to reduce the number of ARBAC rules and users considered during analysis. We also present parallel algorithms that speed up the analysis on multi-core systems. The experimental results show that our techniques significantly reduce the analysis time, making it practical to analyze ARBAC without separate administration. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=101610147
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.3233/JCS-140511
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 29
        StartPage: 1
    Subjects:
      – SubjectFull: Access control
        Type: general
      – SubjectFull: Computer security research
        Type: general
      – SubjectFull: Parallel algorithms
        Type: general
      – SubjectFull: Algorithms
        Type: general
      – SubjectFull: Computer systems
        Type: general
    Titles:
      – TitleFull: Policy analysis for administrative role based access control without separate administration.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Yang, Ping
      – PersonEntity:
          Name:
            NameFull: Gofman, Mikhail I.
      – PersonEntity:
          Name:
            NameFull: Stoller, Scott D.
      – PersonEntity:
          Name:
            NameFull: Yang, Zijiang
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 01
              Text: Jan2015
              Type: published
              Y: 2015
          Identifiers:
            – Type: issn-print
              Value: 0926227X
          Numbering:
            – Type: volume
              Value: 23
            – Type: issue
              Value: 1
          Titles:
            – TitleFull: Journal of Computer Security
              Type: main
ResultId 1