{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,6]],"date-time":"2026-02-06T03:14:25Z","timestamp":1770347665341,"version":"3.49.0"},"reference-count":30,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2006,11,1]],"date-time":"2006-11-01T00:00:00Z","timestamp":1162339200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2006,11]]},"abstract":"<jats:p>\n            The administration of large role-based access control (RBAC) systems is a challenging problem. In order to administer such systems, decentralization of administration tasks by the use of delegation is an effective approach. While the use of delegation greatly enhances flexibility and scalability, it may reduce the control that an organization has over its resources, thereby diminishing a major advantage RBAC has over discretionary access control (DAC). We propose to use security analysis techniques to maintain desirable security properties while delegating administrative privileges. We give a precise definition of a family of security analysis problems in RBAC, which is more general than safety analysis that is studied in the literature. We show that two classes of problems in the family can be reduced to similar analysis in the RT[\u219e\u2229] role-based trust-management language, thereby establishing an interesting relationship between RBAC and the\n            <jats:italic>RT<\/jats:italic>\n            framework. The reduction gives efficient algorithms for answering most kinds of queries in these two classes and establishes the complexity bounds for the intractable cases.\n          <\/jats:p>","DOI":"10.1145\/1187441.1187442","type":"journal-article","created":{"date-parts":[[2007,1,16]],"date-time":"2007-01-16T19:38:29Z","timestamp":1168976309000},"page":"391-420","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":137,"title":["Security analysis in role-based access control"],"prefix":"10.1145","volume":"9","author":[{"given":"Ninghui","family":"Li","sequence":"first","affiliation":[{"name":"Purdue University, West Lafayette, IN"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mahesh V.","family":"Tripunitara","sequence":"additional","affiliation":[{"name":"Motorola Labs, Schaumburg, IL"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2006,11]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/382912.382913"},{"key":"e_1_2_1_2_1","unstructured":"Crampton J. 2002. Authorizations and antichains. Ph.D. thesis Birbeck College University of London UK.  Crampton J. 2002. Authorizations and antichains. Ph.D. thesis Birbeck College University of London UK."},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the Eighth ACM Symposium on Access Control Models and Technologies (SACMAT","author":"Crampton J.","year":"2003"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/762476.762478"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/501978.501980"},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the Eighth ACM Symposium on Access Control Models and Technologies. 10","author":"Ferraiolo D. F."},{"key":"e_1_2_1_7_1","unstructured":"Garey M. R. and Johnson D. J. 1979. Computers And Intractability: A Guide to the Theory of NP-Completeness. Freeman San Francisco CA.   Garey M. R. and Johnson D. J. 1979. Computers And Intractability: A Guide to the Theory of NP-Completeness. Freeman San Francisco CA."},{"key":"e_1_2_1_8_1","volume-title":"Proceedings of the AFIPS Spring Joint Computer Conference.","volume":"40","author":"Graham G. S."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/360303.360333"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/501963.501966"},{"key":"e_1_2_1_11_1","volume-title":"Proceedings of the Seventh European Symposium on Research in Computer Security (ESORICS","author":"Koch M.","year":"2002"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/545186.545191"},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the Ninth ACM Symposium on Access Control Models and Technologies (SACMAT","author":"Koch M.","year":"2004"},{"key":"e_1_2_1_14_1","volume-title":"Protection. In Proceedings of the 5th Princeton Conference on Information Sciences and Systems. Reprinted in ACM Operating Systems Review 8, 1, 18--24 (Jan","author":"Lampson B. W.","year":"1971"},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the Ninth ACM Symposium on Access Control Models and Technologies (SACMAT","author":"Li N.","year":"2004"},{"key":"e_1_2_1_16_1","first-page":"1","article-title":"Distributed credential chain discovery in trust management","volume":"11","author":"Li N.","year":"2003","journal-title":"Journal of Computer Security"},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the 2002 IEEE Symposium on Security and Privacy. IEEE Computer Society Press","author":"Li N."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1066100.1066103"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/322017.322025"},{"key":"e_1_2_1_20_1","volume-title":"Proceedings of INFOSECU99 International Conference on Information and Security.","author":"Munawer Q."},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the Seventh ACM Symposium on Access Control Models and Technologies (SACMAT","author":"Oh S.","year":"2002"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/984334.984339"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/42282.42286"},{"key":"e_1_2_1_24_1","volume-title":"Proceedings of the 1992 IEEE Symposium on Security and Privacy. IEEE Computer Society Press","author":"Sandhu R. S.","year":"1992"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.485845"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/300830.300839"},{"key":"e_1_2_1_27_1","volume-title":"Proceedings of the Sixth ACM Symposium on Access Control Models and Technologies. ACM Press","author":"Schaad A."},{"key":"e_1_2_1_28_1","volume-title":"Proceedings of 11th ACM Conference on Computer and Communications Security (CCS-11)","author":"Tripunitara M. V."},{"key":"e_1_2_1_29_1","volume-title":"Proceedings of the Ninth ACM Symposium on Access Control Models and Technologies (SACMAT","author":"Zhang X.","year":"2004"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1108906.1108908"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1187441.1187442","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1187441.1187442","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:08:11Z","timestamp":1750262891000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1187441.1187442"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006,11]]},"references-count":30,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2006,11]]}},"alternative-id":["10.1145\/1187441.1187442"],"URL":"https:\/\/doi.org\/10.1145\/1187441.1187442","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2006,11]]},"assertion":[{"value":"2006-11-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}