• DocumentCode
    1943946
  • Title

    The Role Hierarchy Mining Problem: Discovery of Optimal Role Hierarchies

  • Author

    Guo, Qi ; Vaidya, Jaideep ; Atluri, Vijayalakshmi

  • Author_Institution
    Rutgers Univ., Newark, NJ
  • fYear
    2008
  • fDate
    8-12 Dec. 2008
  • Firstpage
    237
  • Lastpage
    246
  • Abstract
    Role hierarchies are fundamental to the role based access control (RBAC) model. The notion of role hierarchy is a well understood concept that allows senior roles to inherit the permissions of the corresponding junior roles. Role hierarchies further ease the burden of security administration, as there is no need to explicitly specify and maintain a large number of permissions. Given a set of roles or user permissions, one may construct a number of alternative hierarchies. However, there does not exist the notion of an optimal role hierarchy. Optimality helps in maximizing the benefit of employing the role hierarchy. In this paper, we propose such a formal metric. Our optimality notion is based on the smallest graph representation of the role hierarchy (minimal in the number of edges) having the same transitive closure as any alternate representation. We show why this makes sense as well as ways to achieve this. The main contributions of this paper are to formalize the notion of optimality for role hierarchy construction, along with proposing heuristic solutions to achieve this objective, thus making role hierarchies feasible and practical.
  • Keywords
    authorisation; data mining; graph theory; graph representation; optimal role hierarchy; role based access control; role hierarchy mining problem; Access control; Application software; Computer security; Database systems; Enterprise resource planning; National security; Operating systems; Permission; Qualifications; Software systems; Role Engineering; Role Hierarchy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2008. ACSAC 2008. Annual
  • Conference_Location
    Anaheim, CA
  • ISSN
    1063-9527
  • Print_ISBN
    978-0-7695-3447-3
  • Type

    conf

  • DOI
    10.1109/ACSAC.2008.38
  • Filename
    4721561