Constraint-Aware Role Mining via Extended Boolean Matrix Decomposition

被引:42
|
作者
Lu, Haibing [1 ]
Vaidya, Jaideep [2 ]
Atluri, Vijayalakshmi [2 ]
Hong, Yuan [2 ]
机构
[1] Santa Clara Univ, Leavey Sch Business, Dept Operat Management & Informat Syst, Santa Clara, CA 95053 USA
[2] Rutgers State Univ, Dept Management Sci & Informat Syst, Newark, NJ 07102 USA
基金
美国国家科学基金会;
关键词
RBAC; constraint-aware role mining; EBMD;
D O I
10.1109/TDSC.2012.21
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The role mining problem has received considerable attention recently. Among the many solutions proposed, the Boolean matrix decomposition (BMD) formulation has stood out, which essentially discovers roles by decomposing the binary matrix representing user-to-permission assignment (UPA) into two matrices-user-to-role assignment (UA) and permission-to-role assignment (PA). However, supporting certain embedded constraints, such as separation of duty (SoD) and exceptions, is critical to the role mining process. Otherwise, the mined roles may not capture the inherent constraints of the access control policies of the organization. None of the previously proposed role mining solutions, including BMD, take into account these underlying constraints while mining. In this paper, we extend the BMD so that it reflects such embedded constraints by proposing to allow negative permissions in roles or negative role assignments for users. Specifically, by allowing negative permissions in roles, we are often able to use less roles to reconstruct the same given user-permission assignments. Moreover, from the resultant roles we can discover underlying constraints such as separation of duty constraints. This feature is not supported by any existing role mining approaches. Hence, we call the role mining problem with negative authorizations the constraint-aware role mining problem (CRM). We also explore other interesting variants of the CRM, which may occur in real situations. To enable CRM and its variants, we propose a novel approach, extended Boolean matrix decomposition (EBMD), which addresses the ineffectiveness of BMD in its ability of capturing underlying constraints. We analyze the computational complexity for each of CRM variants and present heuristics for problems that are proven to be NP-hard.
引用
收藏
页码:655 / 669
页数:15
相关论文
共 9 条
  • [1] Role Mining Using Boolean Matrix Decomposition With Hierarchy
    Ye, Wei
    Li, Ruixuan
    Li, Huaqing
    [J]. 2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 805 - 812
  • [2] Extended Boolean Matrix Decomposition
    Lu, Haibing
    Vaidya, Jaideep
    Atluri, Vijayalakshmi
    Hong, Yuan
    [J]. 2009 9TH IEEE INTERNATIONAL CONFERENCE ON DATA MINING, 2009, : 317 - +
  • [3] Optimal Boolean matrix decomposition: Application to role engineering
    Lu, Haibing
    Vaidya, Jaideep
    Atluri, Vijayalakshmi
    [J]. 2008 IEEE 24TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING, VOLS 1-3, 2008, : 297 - +
  • [4] Constraint-aware optimization model for plane truss structures via single-agent gradient descent
    Park, Jun Su
    Hong, Taehoon
    Lee, Dong-Eun
    Park, Hyo Seon
    [J]. COMPUTER-AIDED CIVIL AND INFRASTRUCTURE ENGINEERING, 2024, 39 (18) : 2737 - 2759
  • [5] Collision-Free Visual Servoing of an Eye-in-Hand Manipulator via Constraint-Aware Planning and Control
    Chan, Ambrose
    Leonard, Simon
    Croft, Elizabeth A.
    Little, James J.
    [J]. 2011 AMERICAN CONTROL CONFERENCE, 2011, : 4642 - 4648
  • [6] BEM: Mining Coregulation Patterns in Transcriptomics via Boolean Matrix Factorization
    Liang, Lifan
    Zhu, Kunju
    Lu, Songjian
    [J]. BIOINFORMATICS, 2020, 36 (13) : 4030 - 4037
  • [7] Distributed Informative-Sensor Identification via Sparsity-Aware Matrix Decomposition
    Schizas, Ioannis D.
    [J]. IEEE TRANSACTIONS ON SIGNAL PROCESSING, 2013, 61 (18) : 4610 - 4624
  • [8] CONSTRAINED ROLE-ENGINEERING OPTIMIZATION USING BOOLEAN MATRIX DECOMPOSITION AND INTEGER LINEAR PROGRAMMING TECHNIQUES
    Sun, Wei
    [J]. INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2022, 18 (04): : 1037 - 1053
  • [9] Extended Infrared Target Filtering via Random Finite Set and Low-Rank Matrix Decomposition
    Su, Jian
    Zhou, Haiyin
    Yu, Qi
    Zhu, Jubo
    Liu, Jiying
    [J]. IET SIGNAL PROCESSING, 2024, 2024