Towards automatic update of access control policy

  • Authors:
  • Jinwei Hu;Yan Zhang;Ruixuan Li

  • Affiliations:
  • Intelligent Systems Laboratory, School of Computing and Mathematics, Univ. of Western Sydney, Sydney, Australia and Intelligent and Distributed Computing Laboratory, School of Computer Science and ...;Intelligent Systems Laboratory, School of Computing and Mathematics, University of Western Sydney, Sydney, Australia;Intelligent and Distributed Computing Laboratory, School of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan, China

  • Venue:
  • LISA'10 Proceedings of the 24th international conference on Large installation system administration
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Role-based access control (RBAC) has significantly simplified the management of users and permissions in computing systems. In dynamic environments, systems are subject to changes, so that the associated configurations need to be updated accordingly in order to reflect the systems' evolution. Access control update is complex, especially for large-scale systems; because the updated system is expected to meet necessary constraints. This paper presents a tool, RoleUpdater, which answers administrators' high-level update request for role-based access control systems. RoleUpdater is able to automatically check whether a required update is achievable and, if so, to construct a reference model. In light of this model, administrators could fulfill the changes to RBAC systems. RoleUpdater is able to cope with practical update requests, e.g., that include role hierarchies and administrative rules in effect. Moreover, RoleUp-dater can also provide minimal update in the sense that no redundant changes are implemented.