首页> 外文期刊>Future generation computer systems >Supporting user authorization queries in RBAC systems by role-permission reassignment
【24h】

Supporting user authorization queries in RBAC systems by role-permission reassignment

机译:通过角色权限重新分配支持RBAC系统中的用户授权查询

获取原文
获取原文并翻译 | 示例
       

摘要

TheUser Authorization Query(UAQ) Problem is a key issue related to efficient handling of users’ access requests inRole Based Access Control(RBAC) systems. However, there may not exist any solution to a given UAQ problem due to the limitation caused by the current system state, because missing any requested permission may thwart a task, while an extra permission may bring an intolerable risk to the system. Hence, update of the role–permission assignment is needed to support the feasibility of an UAQ problem. In this paper, we study fundamental problems related to role–permission reassignment, including the RVP problem the goal of which is to determine whether a given role–permission assignment satisfies all reassignment objectives and does not violate any prerequisite constraint or permission-capacity constraint, the RFP problem which verifies whether there exists a valid role–permission assignment, and the RGP problem which studies how to generate a valid role–permission assignment. We present the computational complexity analysis of RVP, RFP and RGP, showing that RVP is solvable in linear time, while both RFP and RGP are NP-hard. We also propose an approach for RGP, which incorporates a preprocessing to decrease the size of the problem, and reduce it to an SAT problem. Finally, experimental results show the validity and effectiveness of our proposed approach.
机译:用户授权查询(UAQ)问题是与基于角色的访问控制(RBAC)系统中用户访问请求的有效处理有关的关键问题。但是,由于当前系统状态引起的限制,对于给定的UAQ问题可能不存在任何解决方案,因为缺少任何请求的许可可能会阻碍任务,而额外的许可可能给系统带来无法承受的风险。因此,需要更新角色权限分配以支持UAQ问题的可行性。在本文中,我们研究与角色-权限重新分配相关的基本问题,包括RVP问题,其目标是确定给定的角色-权限分配是否满足所有重新分配目标,并且不违反任何先决条件约束或权限容量约束,验证是否存在有效角色权限分配的RFP问题,以及研究如何生成有效角色权限分配的RGP问题。我们提出了RVP,RFP和RGP的计算复杂性分析,结果表明RVP在线性时间内是可解决的,而RFP和RGP都是NP-hard。我们还为RGP提出了一种方法,该方法结合了预处理以减小问题的大小并将其减少为SAT问题。最后,实验结果表明了该方法的有效性和有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号