首页> 外文会议>Annual IFIP WG 11.3 conference on data and applications security and privacy >Policy Analysis for Administrative Role Based Access Control without Separate Administration
【24h】

Policy Analysis for Administrative Role Based Access Control without Separate Administration

机译:无需单独管理的基于管理角色的访问控制的策略分析

获取原文

摘要

Access control is widely used in large systems for restricting resource access to authorized users. In particular, role based access control (RBAC) is a generalized approach to access control and is well recognized for its many advantages in managing authorization policies. This paper considers user-role reachability analysis of administrative role based access control (ARBAC), which defines administrative roles and specifies how members of each administrative role can change the RBAC policy. Most existing works on user-role reachability analysis assume the separate administration restriction in ARBAC policies. While this restriction greatly simplifies the user-role reachability analysis, it also limits the expressiveness and applicability of ARBAC. In this paper, we consider analysis of ARBAC without the separate administration restriction and present new techniques to reduce the number of ARBAC rules and users considered during analysis. We also present a number of parallel algorithms that speed up the analysis on multi-core systems. The experimental results show that our techniques significantly reduce the analysis time, making it practical to analyze ARBAC without separate administration.
机译:访问控制广泛用于大型系统中,用于限制对授权用户的资源访问。特别地,基于角色的访问控制(RBAC)是访问控制的一种通用方法,并且由于其在管理授权策略方面的许多优势而广为人知。本文考虑了基于管理角色的访问控制(ARBAC)的用户角色可达性分析,该分析定义了管理角色并指定了每个管理角色的成员如何更改RBAC策略。现有的大多数有关用户角色可达性分析的工作都假设ARBAC策略中存在单独的管理限制。尽管此限制大大简化了用户角色的可达性分析,但它也限制了ARBAC的表示性和适用性。在本文中,我们考虑了没有单独管理限制的ARBAC分析,并提出了减少在分析过程中考虑的ARBAC规则和用户数量的新技术。我们还提出了许多并行算法,这些算法可加快多核系统上的分析速度。实验结果表明,我们的技术大大减少了分析时间,使无需单独管理即可分析ARBAC成为现实。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号