TY - GEN
T1 - Efficient policy analysis for administrative role based access control
AU - Stoller, Scott D.
AU - Yang, Ping
AU - Ramakrishnan, C. R.
AU - Gofman, Mikhail I.
PY - 2007
Y1 - 2007
N2 - Administrative RBAC (ARBAC) policies specify how Role-Based Access Control (RBAC) policies may be changed by each administrator. It is often difficult to fully understand the effect of an ARBAC policy by simple inspection, because sequences of changes by different administrators may interact in unexpected ways. ARBAC policy analysis algorithms can help by answering questions, such a suser-role reachability, which asks whether a given user can be assigned to given roles by given administrators. This problem is intractable in general. This paper identifies classes of policies of practical interest, develops analysis algorithms for them, and analyzes their parameterized complexity, showing that the algorithms may have high complexity with respect to some parameter k characterizing the hardness of the input (such that k is often small in practice) but have polynomial complexity in terms of the overall input size when the value of k is fixed.
AB - Administrative RBAC (ARBAC) policies specify how Role-Based Access Control (RBAC) policies may be changed by each administrator. It is often difficult to fully understand the effect of an ARBAC policy by simple inspection, because sequences of changes by different administrators may interact in unexpected ways. ARBAC policy analysis algorithms can help by answering questions, such a suser-role reachability, which asks whether a given user can be assigned to given roles by given administrators. This problem is intractable in general. This paper identifies classes of policies of practical interest, develops analysis algorithms for them, and analyzes their parameterized complexity, showing that the algorithms may have high complexity with respect to some parameter k characterizing the hardness of the input (such that k is often small in practice) but have polynomial complexity in terms of the overall input size when the value of k is fixed.
UR - https://www.scopus.com/pages/publications/77952403780
U2 - 10.1145/1315245.1315300
DO - 10.1145/1315245.1315300
M3 - Conference contribution
AN - SCOPUS:77952403780
SN - 9781595937032
T3 - Proceedings of the ACM Conference on Computer and Communications Security
SP - 445
EP - 455
BT - CCS'07 - Proceedings of the 14th ACM Conference on Computer and Communications Security
T2 - 14th ACM Conference on Computer and Communications Security, CCS'07
Y2 - 29 October 2007 through 2 November 2007
ER -