DocumentCode
2397451
Title
Enhancing role management in Role-Based Access Control
Author
Feng, Xiaosheng ; Ge, Bin ; Sun, Yang ; Wang, Zhenwen ; Tang, Daquan
Author_Institution
C4ISR Technol. Nat. Defense Sci. & Technol. Key Lab., Nat. Univ. of Defense Technol., Changsha, China
fYear
2010
fDate
26-28 Oct. 2010
Firstpage
677
Lastpage
683
Abstract
Role-Based Access Control (RBAC) has been widely applied to authorize certain users to access certain data or resources within complex systems. Several issues arose during the applications of RBAC models, which include the constraints applied in user-role assignments and role-role relations, revoking redundant roles and assignments, etc. These problems bring high costs in RBAC management. This paper addresses these problems from the perspective of visualization in order to enhance role management in RBAC, particularly leveraging the experience of DAG visualization and the administrative cost. A detailed problem statement is made first, and then a DAG normalization process is proposed to construct a refined role hierarchy. Subsequently, a two-layered paradigm, the lower for displaying role hierarchy and permissions, and the upper for placing users, is presented for the visualization of role management in RBAC. Additionally, some specific interaction techniques are put forward to visually aid in solving the constraint and redundancy problems. A two-stage user observation conducted in laboratory environment suggests the effectiveness and usability of the prototype system for the security administrator in role management of RBAC.
Keywords
access control; computer network security; telecommunication network management; DAG visualization; RBAC models; complex systems; role management; role-based access control; security administrator; Heuristic layout; RBAC; Role Hierarchy; Role Management;
fLanguage
English
Publisher
ieee
Conference_Titel
Broadband Network and Multimedia Technology (IC-BNMT), 2010 3rd IEEE International Conference on
Conference_Location
Beijing
Print_ISBN
978-1-4244-6769-3
Type
conf
DOI
10.1109/ICBNMT.2010.5705176
Filename
5705176
Link To Document