A Role Based Access Control Using Cardinality Constraint Of Role Mining
Keywords:
RBAC, role mining, cardinality constraint, concurrent framework, post-processing frameworkAbstract
Role-based access control (RBAC) has long been recognized as a normative access control model. The essential notion of RBAC is to decouple users and permissions, and then associate both to roles respectively. This substantially simplifies the complexity of users and permissions management, widely perceived as onerous operations by system administrators. Employing RBAC is not only convenient but reduces the complication of access control since the number of roles in an organization is significantly smaller than that of users. Moreover, the use of roles as authorization subjects, instead of users, avoids having to revoke and re-grant authorizations whenever users change their positions and/or duties within the organization. As a result, RBAC has been implemented successfully by numerous information systems. The trend is that RBAC will maintain its increasing prevalence since the growing demand for cost-e activeness in management and security mechanism calls for it. Roles, users, permissions, objects and operations are constituents in RBAC where roles represent organizational agents that perform certain job functions within the organization, users are human beings and permissions are a set of many-to-many relations between objects and operations. According to the RBAC reference model, roles describe the relationship between users and permissions. Roles can be hierarchically structured, where senior roles generally inherit the permissions assigned to junior roles. Additionally, constraints such as separation of duties may be associated with the roles.
References
Pullamsetty Harika, Marreddy Nagajyothi, John C. John, Shamik Sural, Jaideep Vaidya, and Vijayalakshmi Atluri , Meeting Cardinality Constraints in Role Mining IEEE transaction on dependable and secure computing vol. 12, No. 1,January / February 2015.
[2] C. Blundo, S. Cimato, Constrained Role Mining ArXiv e-prints,Mar. 2012.
[3] A. Colantonio, R. Di Pietro, and A. Ocello, A Cost-Driven Approach to RoleEngineering, Proc. ACM Symp. Applied Computing(SAC), pp. 2129-2136, 2008.
[4] M. Frank, A.P. Streich, D. Basin, and J.M. Buhmann, Multi-Assignment Clustering for Boolean Data, J. Machine Learning Research, vol. 13, pp. 459-489,Feb. 2012.
[5] R.S. Sandhu, E.J. Coyne, H.L. Feinstein, and C.E. Youman, Role Based Access Control Models, Computer, vol. 29, no. 2, pp. 8-47, Feb. 1996.
[6] D.F. Ferraiolo, R. Sandhu, S. Gavrila, D.R. Kuhn, and R. Chandramouli,Proposed NIST Standard for Role-Based Access control, ACM Trans. Information and System Security, vol. 4, no. 3, pp. 224-274, 2001.
[7] M. Frank, A.P. Streich, D. Basin, and J.M. Buhmann, A Probabilistic Approach to Hybrid Role Mining, Proc. 16th ACM Conf. Computer and Comm. Security (CCS), pp. 101-111, 2009.
[8] A. Colantonio, R. Di Pietro, A. Ocello, and N.V. Verde, A Formal Framework to Elicit Roles with Business Meaning in RBAC Systems, Proc. 14th ACM Symp. Access Control Models and Technologies (SACMAT), pp. 85-94, 2009.
[9] I. Molloy, N. Li, T. Li, Z. Mao, Q. Wang, and J. Lobo. Evaluating role mining algorithms. In SACMAT'09, pages 95104, 2009.
[10] D. Zhang, R. Kotagiri, and E. Tim, Role Engineering Using Graph Optimization,Proc. 12th ACM Symp. Access Control Models and Technologies (SACMAT), pp.139-144, 2007.
Downloads
Published
Issue
Section
Categories
License

This work is licensed under a Creative Commons Attribution 4.0 International License.
This work is licensed under a Creative Commons Attribution 4.0 International License.
Under this license, authors retain ownership of the copyright for their articles. By submitting to the International Journal of Advanced Research in Science, Management, and Technology (IJARSMT), authors grant the journal the right of first publication. Users are free to share, copy, and redistribute the material in any medium or format, and to adapt, remix, transform, and build upon the material for any purpose, including commercially, provided that appropriate credit is given to the original author(s) and the journal, a link to the license is provided, and any changes made are indicated.
