首页> 外文期刊>Journal of computer security >Towards user-oriented RBAC model
【24h】

Towards user-oriented RBAC model

机译:面向用户的RBAC模型

获取原文
获取原文并翻译 | 示例
       

摘要

Role mining is to define a role set to implement the role-based access control (RBAC) system and regarded as one of the most important and costliest implementation phases. While various role mining models have been proposed, we find that user experience/perception - one ultimate goal for any information system - is surprisingly ignored by the existing works. One advantage of RBAC is to support multiple role assignments and allow a user to activate the necessary role to perform the tasks at each session. However, frequent role activating and deactivating can be a tendinous thing from the user perspective. A user-friendly RBAC system is expected to assign few roles to every user. So in this paper we propose to incorporate to the role mining process a user-role assignment constraint that mandates the maximum number of roles each user can have. Under this rationale, we formulate user-oriented role mining as the user role mining problem, where all users have the same maximal role assignments, the personalized role mining problem, where users can have different maximal role assignments, and the approximate versions of the two problems, which tolerate a certain amount of deviation from the complete reconstruction. The extra constraint on the maximal role assignments poses a great challenge to role mining, which in general is already a hard problem. We examine some typical existing role mining methods to see their applicability to our problems. In light of their insufficiency, we present a new algorithm, which is based on a novel dynamic candidate role generation strategy, tailored to our problems. Experiments on benchmark data sets demonstrate the effectiveness of our proposed algorithm.
机译:角色挖掘是为了定义角色集以实施基于角色的访问控制(RBAC)系统,并且被视为最重要且成本最高的实施阶段之一。虽然已经提出了各种角色挖掘模型,但我们发现用户体验/感知(任何信息系统的最终目标)都被现有作品意外地忽略了。 RBAC的一个优点是支持多个角色分配,并允许用户激活必要的角色以在每个会话中执行任务。但是,从用户的角度来看,频繁激活和停用角色可能是一件容易的事。希望用户友好的RBAC系统可以为每个用户分配很少的角色。因此,在本文中,我们建议将角色角色分配约束合并到角色挖掘过程中,该约束规定每个用户可以拥有的最大角色数量。在此基础上,我们将面向用户的角色挖掘公式化为用户角色挖掘问题,其中所有用户都具有相同的最大角色分配;个性化角色挖掘问题中,用户可以具有不同的最大角色分配;以及两者的近似版本问题,可以容忍与完整重建之间的一定程度的偏差。最大角色分配的额外约束给角色挖掘带来了巨大挑战,这通常已经是一个难题。我们研究了一些典型的现有角色挖掘方法,以了解它们对我们的问题的适用性。鉴于他们的不足,我们提出了一种新算法,该算法基于针对我们问题的新颖动态候选角色生成策略。在基准数据集上进行的实验证明了我们提出的算法的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号