Title
Extending A Role Graph For Role-Based Access Control
Abstract
Role-based access control (RBAC) is widely used as an access control mechanism in various computer systems. Since an organization's lines of authority influence the authorized privileges of jobs, roles also form a hierarchical structure. A role graph is a model that represents role hierarchies and is suitable for the runtime phase of RBAC deployment. Since a role graph cannot take various forms for given roles and cannot handle abstraction of roles well, however, it is not suitable for the design phase of RBAC deployment. Hence, an extended role graph, which can take a more flexible form than that of a role graph, is proposed. The extended role graph improves diversity and clarifies abstraction of roles, making it suitable for the design phase. An equivalent transformation algorithm (ETA), for transforming an extended role graph into an equivalent role graph, is also proposed. Using the ETA, system administrators can deploy efficiently RBAC by using an extended role graph in the design phase and a standard role graph in the runtime phase.
Year
DOI
Venue
2009
10.1587/transinf.E92.D.211
IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS
Keywords
Field
DocType
RBAC, role graph, transformation algorithm, equivalence
Graph,Abstraction,Software deployment,Computer science,Role-based access control,Theoretical computer science,Equivalence (measure theory),Wait-for graph,Access control,Hierarchy,Distributed computing
Journal
Volume
Issue
ISSN
E92D
2
1745-1361
Citations 
PageRank 
References 
1
0.43
7
Authors
2
Name
Order
Citations
PageRank
Yoshiharu Asakura121.20
Yukikazu Nakamoto27921.50