Open AccessPosted Content
Constrained Role Mining
Carlo Blundo,Stelvio Cimato +1 more
TL;DR: In this paper, a formal definition of the role mining problem under the cardinality constraint is provided, i.e., restricting the maximum number of permissions that can be included in a role.
read more
Abstract: Role Based Access Control (RBAC) is a very popular access control model, for long time investigated and widely deployed in the security architecture of different enterprises. To implement RBAC, roles have to be firstly identified within the considered organization. Usually the process of (automatically) defining the roles in a bottom up way, starting from the permissions assigned to each user, is called {\it role mining}. In literature, the role mining problem has been formally analyzed and several techniques have been proposed in order to obtain a set of valid roles.
Recently, the problem of defining different kind of constraints on the number and the size of the roles included in the resulting role set has been addressed. In this paper we provide a formal definition of the role mining problem under the cardinality constraint, i.e. restricting the maximum number of permissions that can be included in a role. We discuss formally the computational complexity of the problem and propose a novel heuristic. Furthermore we present experimental results obtained after the application of the proposed heuristic on both real and synthetic datasets, and compare the resulting performance to previous proposals
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
A Survey of Role Mining
TL;DR: This article comprehensively study and classify the basic problem of role mining along with its several variants and the corresponding solution strategies, and discusses the limitations of existing work and identify new areas of research that can lead to further enrichment of this field.
111
Migrating from RBAC to temporal RBAC
TL;DR: Two temporal role mining approaches that enable migration from RBAC to TRBAC are proposed that make use of conventional (non-temporal) role mining algorithms and are both efficient and effective.
28
Policy Engineering in RBAC and ABAC
Saptarshi Das,Barsha Mitra,Vijayalakshmi Atluri,Jaideep Vaidya,Shamik Sural +4 more
- 01 Jan 2018
TL;DR: The role mining problem and the policy engineering problem in RBAC and ABAC are explored along with their existing solution strategies and future directions of research in these two areas are identified.
27
Mining temporal roles using many-valued concepts
TL;DR: This paper formally defines the temporal role mining problem (TRMP) in the form of a matrix decomposition problem, by introducing a new operator that multiplies a set with a Boolean value and redefining existing matrix multiplication operations in terms of it.
22
The generalized temporal role mining problem
TL;DR: This paper formally defines the problem of finding a minimal set of roles from temporal user-permission assignments, such that in the resulting TRBAC system, users acquire either the same or a subset of the permissions originally assigned to them for the complete or partial durations of time as specified in the input.
22
References
Reducibility Among Combinatorial Problems.
Richard M. Karp
- 01 Jan 1972
TL;DR: Throughout the 1960s I worked on combinatorial optimization problems including logic circuit design with Paul Roth and assembly line balancing and the traveling salesman problem with Mike Held, which made me aware of the importance of distinction between polynomial-time and superpolynomial-time solvability.
13.6K
Reducibility Among Combinatorial Problems
TL;DR: The work of Dantzig, Fulkerson, Hoffman, Edmonds, Lawler and other pioneers on network flows, matching and matroids acquainted me with the elegant and efficient algorithms that were sometimes possible.
8.7K
Role-based access control models
TL;DR: Why RBAC is receiving renewed attention as a method of security administration and review is explained, a framework of four reference models developed to better understandRBAC is described, and the use of RBAC to manage itself is discussed.
6.1K
Proposed NIST standard for role-based access control
TL;DR: Although RBAC continues to evolve as users, researchers, and vendors gain experience with its application, the features and components proposed in this standard represent a fundamental and stable set of mechanisms that may be enhanced by developers in further meeting the needs of their customers.