Towards user-oriented RBAC model

被引:14
|
作者
Lu, Haibing [1 ]
Hong, Yuan [2 ]
Yang, Yanjiang [3 ]
Duan, Lian [4 ]
Badar, Nazia [5 ]
机构
[1] Santa Clara Univ, Santa Clara, CA 95053 USA
[2] SUNY Albany, Albany, NY 12222 USA
[3] Inst Infocomm Res, Singapore, Singapore
[4] New Jersey Inst Technol, Newark, NJ 07102 USA
[5] Rutgers State Univ, Newark, NJ 07102 USA
关键词
Role-based access control; role mining; user-oriented; optimization; heuristic algorithm;
D O I
10.3233/JCS-140519
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Role mining is to define a role set to implement the role-based access control (RBAC) system and regarded as one of the most important and costliest implementation phases. While various role mining models have been proposed, we find that user experience/perception - one ultimate goal for any information system - is surprisingly ignored by the existing works. One advantage of RBAC is to support multiple role assignments and allow a user to activate the necessary role to perform the tasks at each session. However, frequent role activating and deactivating can be a tendinous thing from the user perspective. A user-friendly RBAC system is expected to assign few roles to every user. So in this paper we propose to incorporate to the role mining process a user-role assignment constraint that mandates the maximum number of roles each user can have. Under this rationale, we formulate user-oriented role mining as the user role mining problem, where all users have the same maximal role assignments, the personalized role mining problem, where users can have different maximal role assignments, and the approximate versions of the two problems, which tolerate a certain amount of deviation from the complete reconstruction. The extra constraint on the maximal role assignments poses a great challenge to role mining, which in general is already a hard problem. We examine some typical existing role mining methods to see their applicability to our problems. In light of their insufficiency, we present a new algorithm, which is based on a novel dynamic candidate role generation strategy, tailored to our problems. Experiments on benchmark data sets demonstrate the effectiveness of our proposed algorithm.
引用
收藏
页码:107 / 129
页数:23
相关论文
共 50 条
  • [1] Towards User-Oriented RBAC Model
    Lu, Haibing
    Hong, Yuan
    Yang, Yanjiang
    Duan, Lian
    Badar, Nazia
    [J]. DATA AND APPLICATIONS SECURITY AND PRIVACY XXVII, 2013, 7964 : 81 - 96
  • [2] Towards User-Oriented Steganography
    Ogiela, Urszula
    Ogiela, Marek R.
    [J]. ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 4, AINA 2024, 2024, 202 : 159 - 165
  • [3] Towards User-Oriented Application Composition
    Sanchez, Ivan
    Davidyuk, Oleg
    Riekki, Jukka
    [J]. FCST 2009: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON FRONTIER OF COMPUTER SCIENCE AND TECHNOLOGY, 2009, : 698 - +
  • [4] A User-Oriented Model for Expert Finding
    Smirnova, Elena
    Balog, Krisztian
    [J]. ADVANCES IN INFORMATION RETRIEVAL, 2011, 6611 : 580 - +
  • [5] A User-Oriented Web Service Reliability Model
    Li, Bixin
    Su, Zhiyong
    Zhou, Ying
    Gong, Xufang
    [J]. 2008 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN AND CYBERNETICS (SMC), VOLS 1-6, 2008, : 3611 - 3616
  • [6] A User-Oriented Trust Model for Web Services
    Li, Bixin
    Song, Rui
    Liao, Li
    Liu, Cuicui
    [J]. 2013 IEEE SEVENTH INTERNATIONAL SYMPOSIUM ON SERVICE-ORIENTED SYSTEM ENGINEERING (SOSE 2013), 2013, : 224 - 232
  • [7] USER-ORIENTED DENTAL-CARE MODEL
    MARCUS, M
    JOHNSON, N
    DRABEK, L
    SUE, G
    [J]. COMPUTERS IN BIOLOGY AND MEDICINE, 1978, 8 (03) : 207 - 222
  • [8] User-oriented Assessment of Classification Model Understandability
    Allahyari, Hiva
    Lavesson, Niklas
    [J]. ELEVENTH SCANDINAVIAN CONFERENCE ON ARTIFICIAL INTELLIGENCE (SCAI 2011), 2011, 227 : 11 - 19
  • [9] A USER-ORIENTED SOFTWARE-RELIABILITY MODEL
    CHEUNG, RC
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 1980, 6 (02) : 118 - 125
  • [10] USER-ORIENTED INFERENCE
    SCHERVISH, MJ
    [J]. JOURNAL OF THE AMERICAN STATISTICAL ASSOCIATION, 1983, 78 (383) : 611 - 615