首页> 外文会议>International symposium on cyberspace safety and security >Supporting User Authorization Queries in RBAC Systems by Role-Permission Reassignment
【24h】

Supporting User Authorization Queries in RBAC Systems by Role-Permission Reassignment

机译:通过角色权限重新分配支持RBAC系统中的用户授权查询

获取原文

摘要

The User Authorization Query (UAQ) Problem is a key issue related to efficiently handling users' access requests in RBAC systems. In practice, there may not exist any solution for the UAQ problem, as missing any requested permissions may make the failure of this task, while any extra permissions may bring the intolerable risk to the system. Hence, making a desirable update of the RBAC system state to support the UAQ problem is desirable. However, this task is generally complex and challenging as usually the resulting state is expected to meet various necessary objectives and constraints. In this paper, we study a fundamental problem of how generate a valid role-permission assignment to satisfy all objectives and constraints, such as reassignment objectives, prerequisite constraints and permission-capacity constraints. The computational complexity result shows that it is intractable (NP-complete) in general. We also propose an approach to reduce it to SAT that benefit from SAT solvers to reduce the running time. Experiment results show that the proposed approach scales well in large RBAC systems.
机译:用户授权查询(UAQ)问题是与有效处理RBAC系统中的用户访问请求有关的关键问题。在实践中,可能没有针对UAQ问题的任何解决方案,因为缺少任何请求的权限可能会使此任务失败,而任何额外的权限都可能给系统带来无法承受的风险。因此,期望对RBAC系统状态进行期望的更新以支持UAQ问题。但是,此任务通常很复杂且具有挑战性,因为通常期望结果状态满足各种必要的目标和约束。在本文中,我们研究了一个基本问题,即如何生成有效的角色权限分配来满足所有目标和约束,例如重新分配目标,先决条件约束和许可能力约束。计算复杂度结果表明它通常是难处理的(NP完全)。我们还提出了一种将其简化为SAT的方法,该方法得益于SAT解算器以减少运行时间。实验结果表明,该方法在大型RBAC系统中具有很好的伸缩性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号