{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T05:25:00Z","timestamp":1784093100674,"version":"3.55.0"},"reference-count":43,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2011,5,1]],"date-time":"2011-05-01T00:00:00Z","timestamp":1304208000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100000038","name":"Natural Sciences and Engineering Research Council of Canada","doi-asserted-by":"publisher","award":["STPGP 322192-05"],"award-info":[{"award-number":["STPGP 322192-05"]}],"id":[{"id":"10.13039\/501100000038","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2011,5]]},"abstract":"<jats:p>As distributed applications increase in size and complexity, traditional authorization architectures based on a dedicated authorization server become increasingly fragile because this decision point represents a single point of failure and a performance bottleneck. Authorization caching, which enables the reuse of previous authorization decisions, is one technique that has been used to address these challenges.<\/jats:p>\n          <jats:p>This article introduces and evaluates the mechanisms for authorization \u201crecycling\u201d in RBAC enterprise systems. The algorithms that support these mechanisms allow making precise and approximate authorization decisions, thereby masking possible failures of the authorization server and reducing its load. We evaluate these algorithms analytically as well as using simulation and a prototype implementation. Our evaluation results demonstrate that authorization recycling can improve the performance of distributed-access control mechanisms.<\/jats:p>","DOI":"10.1145\/1952982.1952985","type":"journal-article","created":{"date-parts":[[2011,6,6]],"date-time":"2011-06-06T11:51:38Z","timestamp":1307361098000},"page":"1-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["Authorization recycling in hierarchical RBAC systems"],"prefix":"10.1145","volume":"14","author":[{"given":"Qiang","family":"Wei","sequence":"first","affiliation":[{"name":"CCB International (Holdings) Ltd., Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jason","family":"Crampton","sequence":"additional","affiliation":[{"name":"Royal Holloway, University of London, U.K."}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Konstantin","family":"Beznosov","sequence":"additional","affiliation":[{"name":"University of British Columbia, Vancouver, BC, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Matei","family":"Ripeanu","sequence":"additional","affiliation":[{"name":"University of British Columbia, Vancouver, BC, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2011,6,6]]},"reference":[{"key":"e_1_2_1_1_1","first-page":"143","article-title":"Zipf's law and the Internet","volume":"3","author":"Adamic L.","year":"2002","journal-title":"Glottometrics"},{"key":"e_1_2_1_2_1","volume-title":"ANSI INCITS 359-2004 for role based access control"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/374308.374365"},{"key":"e_1_2_1_4_1","volume-title":"Secure computer systems: A mathematical model. Tech. rep. MTR-2547","author":"Bell D."},{"key":"e_1_2_1_5_1","volume-title":"Secure computer systems: Mathematical foundations. Tech. rep. MTR-2547","author":"Bell D."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1146269.1146285"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102142"},{"key":"e_1_2_1_8_1","volume-title":"Proceedings of the Annual Joint Conference of the IEEE Computer and Communications Societies. IEEE Computer Society Press","author":"Breslau L."},{"key":"e_1_2_1_9_1","unstructured":"B\u00fccker A. Antonius J. Riexinger D. Sommer F. and Sumida A. 2003. Enterprise Business Portals II with IBM Tivoli Access Manager. IBM Redbooks Armonk NY ibm.com\/redbooks.  B\u00fccker A. Antonius J. Riexinger D. Sommer F. and Sumida A. 2003. Enterprise Business Portals II with IBM Tivoli Access Manager. IBM Redbooks Armonk NY ibm.com\/redbooks."},{"key":"e_1_2_1_10_1","volume-title":"OASIS eXtensible Access Control Markup Language (XACML) v. 2.0","author":"Committee"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1133058.1133075"},{"key":"e_1_2_1_12_1","unstructured":"DeMichiel L. G. Yal\u00e7inalp L. \u00dc. and Krishnan S. 2001. Enterprise JavaBeans v. 2.0. Sun. Oracle Redwood Shores CA.  DeMichiel L. G. Yal\u00e7inalp L. \u00dc. and Krishnan S. 2001. Enterprise JavaBeans v. 2.0. Sun. Oracle Redwood Shores CA."},{"key":"e_1_2_1_13_1","volume-title":"GetAccess design and administration guide","author":"Entrust"},{"key":"e_1_2_1_14_1","volume-title":"Proceedings of the 15th NIST-NCSC National Computer Security Conference","author":"Ferraiolo D."},{"key":"e_1_2_1_15_1","unstructured":"Francis W. and Kucera H. 1967. Computational Analysis of Present-Day American English. Brown University Press Providence RI.  Francis W. and Kucera H. 1967. Computational Analysis of Present-Day American English. Brown University Press Providence RI."},{"key":"e_1_2_1_16_1","first-page":"41","article-title":"The DCE security service","volume":"46","author":"Gittler F.","year":"1995","journal-title":"Hewlett-Packard J."},{"key":"e_1_2_1_17_1","unstructured":"Internet2. 2008. Shibboleth system. http:\/\/shibboleth.internet2.edu.  Internet2. 2008. Shibboleth system. http:\/\/shibboleth.internet2.edu."},{"key":"e_1_2_1_18_1","volume-title":"Fault-Tolerant Computer System Design","author":"Johnson B."},{"key":"e_1_2_1_19_1","series-title":"Lecture Notes in Computer Science","volume-title":"A review of the SESAME development","author":"Kaijser P."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2005.31"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/762476.762479"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028796"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/968559.968563"},{"key":"e_1_2_1_24_1","unstructured":"Markoff J. and Hansell S. 2006. Google's not-so-very-secret weapon. International Herald Tribune. June 13.  Markoff J. and Hansell S. 2006. Google's not-so-very-secret weapon. International Herald Tribune. June 13."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.5555\/645474.653879"},{"key":"e_1_2_1_26_1","volume-title":"Siteminder concepts guide. Tech. rep","author":"Netegrity 0."},{"key":"e_1_2_1_27_1","volume-title":"Proceedings of the 1997 IEEE Symposium on Security and Privacy. IEEE Computer Society Press","author":"Nicomette V."},{"key":"e_1_2_1_28_1","volume-title":"Common object services specification, security service specification v1.8"},{"key":"e_1_2_1_29_1","volume-title":"Oracle entitlements server: Programming security for web services. Tech. rep","author":"Oracle"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1007568.1007631"},{"key":"e_1_2_1_31_1","volume-title":"Proceedings of AWCDAS. Kluwer","author":"Rosenthal A."},{"key":"e_1_2_1_32_1","unstructured":"Ryutov T. and Neuman C. 2000. Generic authorization and access control application program interface: C-bindings. Internet Draft draft-ietf-cat-gaa-bind-03 Internet Engineering Task Force. www.ietf.orgo.  Ryutov T. and Neuman C. 2000. Generic authorization and access control application program interface: C-bindings. Internet Draft draft-ietf-cat-gaa-bind-03 Internet Engineering Task Force. www.ietf.orgo."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1975.9939"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.485845"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/373256.373257"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2006.437"},{"key":"e_1_2_1_37_1","volume-title":"Unified access management: A model for integrated Web security. Tech. rep. Securant Technologies","author":"Securant"},{"key":"e_1_2_1_38_1","volume-title":"Proceedings of the 8th USENIX Security Symposium. USENIX Berkeley, CA, 123--140","author":"Spencer R."},{"key":"e_1_2_1_39_1","volume-title":"Proceedings of the 16th ACM\/IEEE International Symposium on High-Performance Distributed Computing. ACM Press","author":"Strong P.","year":"2007"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542207.1542232"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1266840.1266870"},{"key":"e_1_2_1_42_1","volume-title":"Proceedings of the 5th International Middleware Conference. ACM Press","author":"Vogels W.","year":"2004"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1272366.1272375"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1952982.1952985","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1952982.1952985","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:59:41Z","timestamp":1750244381000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1952982.1952985"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,5]]},"references-count":43,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2011,5]]}},"alternative-id":["10.1145\/1952982.1952985"],"URL":"https:\/\/doi.org\/10.1145\/1952982.1952985","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,5]]},"assertion":[{"value":"2008-10-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2010-04-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-06-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}