首页> 外文期刊>Computers & Security >Towards complexity analysis of User Authorization Query problem in RBAC
【24h】

Towards complexity analysis of User Authorization Query problem in RBAC

机译:RBAC中用户授权查询问题的复杂度分析

获取原文
获取原文并翻译 | 示例

摘要

The User Authorization Query (UAQ) problem for RBAC is to determine whether there exists an optimum set of roles to be activated to provide a particular set of permissions requested by a user. It is a key issue related to efficiently handling users' access requests. Previous definitions of the UAQ problem have considered only the optimization objective for the number of permissions whereas the optimization objective for the number of roles, which is also equally important, has been largely ignored. Moreover, little attention has been given to the computational complexity of the UAQ problem that considers the optimization objectives for both the numbers of permissions and roles. In this paper, we propose a more comprehensive definition of the UAQ problem, which includes irreducibility, role-cardinality and permission-cardinality constraints, and consider both these optimization objectives together. In particular, we study the computational complexity of the UAQ problem by dividing it into three subcases: exact match, safe match and available match, and show that many instances in each subcase with additional constraints are intractable. We also propose an approach for solving the intractable cases of the UAQ problem; the proposed approach incorporates static pruning, preprocessing and the depth-first search based algorithm to significantly reduce the running time.
机译:RBAC的用户授权查询(UAQ)问题是确定是否存在要激活的最佳角色集,以提供用户请求的特定权限集。这是与有效处理用户访问请求有关的关键问题。 UAQ问题的先前定义只考虑了许可数量的优化目标,而角色数量的优化目标(同样重要)也被很大程度上忽略了。此外,很少考虑到UAQ问题的计算复杂性,该问题考虑了权限和角色数量的优化目标。在本文中,我们为UAQ问题提出了更全面的定义,其中包括不可约性,角色基数和权限基数约束,并将这两个优化目标一起考虑。尤其是,我们通过将UAQ问题分为三个子案例来研究其计算复杂性:精确匹配,安全匹配和可用匹配,并证明在每个带有附加约束的子案例中,很多实例是难以解决的。我们还提出了一种解决UAQ问题棘手问题的方法。所提出的方法结合了静态修剪,预处理和基于深度优先搜索的算法,从而大大减少了运行时间。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号