Skip to main navigation Skip to search Skip to main content

Policy analysis for administrative role based access control

  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

72 Scopus citations

Abstract

Role-Based Access Control (RBAC) is a widely used model for expressing access control policies. In large organizations, the RBAC policy may be collectively managed by many administrators. Administrative RBAC (ARBAC) is a model for expressing the authority of administrators, thereby specifying how an organization's RBAC policy may change. Changes by one administrator may interact in unintended ways with changes by other administrators. Consequently, the effect of an ARBAC policy is hard to understand by simple inspection. In this paper, we consider the problem of analyzing ARBAC policies, in particular to determine reachability properties (e.g., whether a user can eventually be assigned to a role by a group of administrators) and availability properties (e.g., whether a user cannot be removed from a role by a group of administrators) implied by a policy. We first establish the connection between security policy analysis and planning in Artificial Intelligence. Based partly on this connection, we show that reachability analysis for ARBAC is PSPACE-complete. We also give algorithms and complexity results for reachability and related analysis problems for several categories of ARBAC policies, defined by simple restrictions on the policy language.

Original languageEnglish
Title of host publicationProceedings - 19th IEEE Computer Security Foundations Workshop, CSFW 2006
PublisherIEEE Computer Society
Pages133-138
Number of pages6
ISBN (Print)0769526152, 9780769526157
DOIs
StatePublished - 2006
Event19th IEEE Computer Security Foundations Workshop, CSFW 2006 - Venice, Italy
Duration: Jul 5 2006Jul 7 2006

Publication series

NameProceedings of the Computer Security Foundations Workshop
Volume2006
ISSN (Print)1063-6900

Conference

Conference19th IEEE Computer Security Foundations Workshop, CSFW 2006
Country/TerritoryItaly
CityVenice
Period07/5/0607/7/06

Fingerprint

Dive into the research topics of 'Policy analysis for administrative role based access control'. Together they form a unique fingerprint.

Cite this