Symbolic reachability analysis for parameterized administrative role-based access control

被引:20
|
作者
Stoller, Scott D. [1 ]
Yang, Ping [2 ]
Gofman, Mikhail I. [2 ]
Ramakrishnan, C. R. [1 ]
机构
[1] SUNY Stony Brook, Dept Comp Sci, Stony Brook, NY 11794 USA
[2] SUNY Binghamton, Dept Comp Sci, Binghamton, NY 13902 USA
基金
美国国家科学基金会;
关键词
Policy analysis; Policy administration; Role-based access control; RBAC; VERIFICATION; SYSTEMS;
D O I
10.1016/j.cose.2010.08.002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Role-based access control (RBAC) is a widely used access control paradigm. In large organizations, the RBAC policy is managed by multiple administrators. An administrative role-based access control (ARBAC) policy specifies how each administrator may change the RBAC policy. It is often difficult to fully understand the effect of an ARBAC policy by simple inspection, because sequences of changes by different administrators may interact in unexpected ways. ARBAC policy analysis algorithms can help by answering questions, such as user-role reachability, which asks whether a given user can be assigned to given roles by given administrators. Allowing roles and permissions to have parameters significantly enhances the scalability, flexibility, and expressiveness of ARBAC policies. This paper defines PARBAC, which extends the classic ARBAC97 model to support parameters, proves that user-role reachability analysis for PARBAC is undecidable when parameters may range over infinite types, and presents a semi-decision procedure for reachability analysis of PARBAC. To the best of our knowledge, this is the first analysis algorithm specifically for parameterized ARBAC policies. We evaluate its efficiency by analyzing its parameterized complexity and benchmarking it on case studies and synthetic policies. We also experimentally evaluate the effectiveness of several optimizations. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:148 / 164
页数:17
相关论文
共 50 条
  • [1] Symbolic Reachability Analysis for Parameterized Administrative Role Based Access Control
    Stoller, Scott D.
    Yang, Ping
    Gofman, Mikhail
    Ramakrishnan, C. R.
    [J]. SACMAT'09: PROCEEDINGS OF THE 14TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2009, : 165 - 174
  • [2] Policy analysis for Administrative Role-Based Access Control
    Sasturkar, Amit
    Yang, Ping
    Stoller, Scott D.
    Ramakrishnan, C. R.
    [J]. THEORETICAL COMPUTER SCIENCE, 2011, 412 (44) : 6208 - 6234
  • [3] Scalable automated symbolic analysis of administrative role-based access control policies by SMT solving
    Armando, Alessandro
    Ranise, Silvio
    [J]. JOURNAL OF COMPUTER SECURITY, 2012, 20 (04) : 309 - 352
  • [4] A formal model for parameterized role-based access control
    Abdallah, AE
    Khayat, EJ
    [J]. FORMAL ASPECTS IN SECURITY AND TRUST, 2005, 173 : 233 - 246
  • [5] Parameterized Role-Based Access Control Policies for XML Documents
    Mueldner, Tomasz
    Leighton, Gregory
    Miziolek, Jan Krzysztof
    [J]. INFORMATION SECURITY JOURNAL, 2009, 18 (06): : 282 - 296
  • [6] User-Role Reachability Analysis of Evolving Administrative Role Based Access Control
    Gofman, Mikhail I.
    Luo, Ruiqi
    Yang, Ping
    [J]. COMPUTER SECURITY-ESORICS 2010, 2010, 6345 : 455 - 471
  • [7] Scalable and Precise Automated Analysis of Administrative Temporal Role-Based Access Control
    Ranise, Silvio
    Truong, Anh
    Armando, Alessandro
    [J]. PROCEEDINGS OF THE 19TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES (SACMAT'14), 2014, : 103 - 114
  • [8] Security Analysis of Administrative Role-Based Access Control Policies with Contextual Information
    Khai Kim Quoc Dinh
    Tuan Duc Tran
    Anh Truong
    [J]. FUTURE DATA AND SECURITY ENGINEERING, 2017, 10646 : 243 - 261
  • [9] VAC - Verifier of Administrative Role-Based Access Control Policies
    Ferrara, Anna Lisa
    Madhusudan, P.
    Nguyen, Truc L.
    Parlato, Gennaro
    [J]. COMPUTER AIDED VERIFICATION, CAV 2014, 2014, 8559 : 184 - 191
  • [10] Planning User Assignment in Administrative Role-Based Access Control
    Huang, Wei
    Yang, Yang
    [J]. 2009 ISECS INTERNATIONAL COLLOQUIUM ON COMPUTING, COMMUNICATION, CONTROL, AND MANAGEMENT, VOL IV, 2009, : 615 - +