首页> 外文期刊>Computers & Security >Symbolic reachability analysis for parameterized administrative role-based access control
【24h】

Symbolic reachability analysis for parameterized administrative role-based access control

机译:符号可达性分析,用于基于参数化的基于角色的管理访问控制

获取原文
获取原文并翻译 | 示例
       

摘要

Role-based access control (RBAC) is a widely used access control paradigm. In large organizations, the RBAC policy is managed by multiple administrators. An administrative role-based access control (ARBAC) policy specifies how each administrator may change the RBAC policy. It is often difficult to fully understand the effect of an ARBAC policy by simple inspection, because sequences of changes by different administrators may interact in unexpected ways. ARBAC policy analysis algorithms can help by answering questions, such as user-role reachability, which asks whether a given user can be assigned to given roles by given administrators. Allowing roles and permissions to have parameters significantly enhances the scalability, flexibility, and expressiveness of ARBAC policies. This paper defines PARBAC, which extends the classic ARBAC97 model to support parameters, proves that user-role reachability analysis for PARBAC is undecidable when parameters may range over infinite types, and presents a semi-decision procedure for reachability analysis of PARBAC. To the best of our knowledge, this is the first analysis algorithm specifically for parameterized ARBAC policies. We evaluate its efficiency by analyzing its parameterized complexity and benchmarking it on case studies and synthetic policies. We also experimentally evaluate the effectiveness of several optimizations.
机译:基于角色的访问控制(RBAC)是一种广泛使用的访问控制范例。在大型组织中,RBAC策略由多个管理员管理。基于管理角色的访问控制(ARBAC)策略指定每个管理员如何更改RBAC策略。通常很难通过简单的检查来完全理解ARBAC策略的效果,因为不同管理员的更改序列可能以意想不到的方式交互。 ARBAC策略分析算法可以通过回答诸如用户角色可达性之类的问题来提供帮助,该问题询问给定管理员是否可以将给定用户分配给给定角色。允许角色和权限具有参数可以显着增强ARBAC策略的可伸缩性,灵活性和可表达性。本文定义了PARBAC,它扩展了经典的ARBAC97模型以支持参数,证明了当参数可能在无限类型范围内时,无法确定PARBAC的用户角色可达性分析,并提出了PARBAC可达性分析的半决策程序。据我们所知,这是第一个专门针对参数化ARBAC策略的分析算法。我们通过分析其参数化的复杂性并在案例研究和综合政策中对其进行基准评估来评估其效率。我们还通过实验评估了几种优化的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号