{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T10:59:07Z","timestamp":1777805947245,"version":"3.51.4"},"reference-count":42,"publisher":"SAGE Publications","issue":"1","license":[{"start":{"date-parts":[[2015,3,15]],"date-time":"2015-03-15T00:00:00Z","timestamp":1426377600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2015,3,15]]},"abstract":"<jats:p>Role mining, the process of deriving a set of roles from the available user-permission assignments, is considered to be an essential step in successful implementation of Role-Based Access Control (RBAC) systems. Traditional role mining techniques, however, are not equipped to handle temporal extensions of RBAC like the Temporal-RBAC (TRBAC) model. In this paper, we formally define the problem of finding a minimal set of roles from temporal user-permission assignments, such that in the resulting TRBAC system, users acquire either the same or a subset of the permissions originally assigned to them for the complete or partial durations of time as specified in the input. We show that the problem is NP-complete and propose a greedy algorithm for solving it. Our algorithm first derives a set of candidate roles from the temporal user-permission assignments and then selects the least possible number of roles from the candidate role set. The final output consists of a set of roles, a user-to-role assignment relation, a role-to-permission assignment relation and a role enabling base describing the time durations for which each role is enabled. Performance of the proposed approach has been evaluated on a number of synthetic as well as real-world datasets.<\/jats:p>","DOI":"10.3233\/jcs-140512","type":"journal-article","created":{"date-parts":[[2016,5,18]],"date-time":"2016-05-18T03:46:51Z","timestamp":1463543211000},"page":"31-58","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":14,"title":["The generalized temporal role mining problem"],"prefix":"10.1177","volume":"23","author":[{"given":"Barsha","family":"Mitra","sequence":"first","affiliation":[{"name":"School of Information Technology, IIT Kharagpur, Kharagpur, India. E-mails:\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shamik","family":"Sural","sequence":"additional","affiliation":[{"name":"School of Information Technology, IIT Kharagpur, Kharagpur, India. E-mails:\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vijayalakshmi","family":"Atluri","sequence":"additional","affiliation":[{"name":"MSIS Department, Rutgers University, Piscataway, NJ, USA. E-mails:\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jaideep","family":"Vaidya","sequence":"additional","affiliation":[{"name":"MSIS Department, Rutgers University, Piscataway, NJ, USA. E-mails:\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2015,3,15]]},"reference":[{"key":"ref001","doi-asserted-by":"crossref","unstructured":"A.\u00a0Baumgrass and M.\u00a0Strembeck, An approach to bridge the gap between role mining and role engineering via migration guides, in: Proceedings of 7th International Conference on Availability, Reliability and Security (ARES), 2012, pp.\u00a0113\u2013122.","DOI":"10.1109\/ARES.2012.77"},{"key":"ref002","doi-asserted-by":"publisher","DOI":"10.1145\/501978.501979"},{"key":"ref003","doi-asserted-by":"crossref","unstructured":"C.\u00a0Blundo and S.\u00a0Cimato, A simple role mining algorithm, in: Proceedings of 25th ACM Symposium on Applied Computing (SAC), 2010, pp.\u00a01958\u20131962.","DOI":"10.1145\/1774088.1774503"},{"key":"ref004","doi-asserted-by":"crossref","unstructured":"C.\u00a0Blundo and S.\u00a0Cimato, Constrained role mining, in: Proceedings of 8th International Workshop on Security and Trust Management, 2012, pp.\u00a0289\u2013304.","DOI":"10.1007\/978-3-642-38004-4_19"},{"key":"ref005","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2010.01.001"},{"key":"ref006","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2011.37"},{"key":"ref007","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2012.01.005"},{"key":"ref008","unstructured":"E.J.\u00a0Coyne, Role engineering, in: Proceedings of 1st ACM Workshop on Role Based Access Control, 1995, pp.\u00a015\u201316."},{"key":"ref009","doi-asserted-by":"crossref","unstructured":"A.\u00a0Ene, W.\u00a0Horne, N.\u00a0Milosavljevic, P.\u00a0Rao, R.\u00a0Schreiber and R.E.\u00a0Tarjan, Fast exact and heuristic methods for role minimization problems, in: Proceedings of 13th ACM Symposium on Access Control Models and Technologies (SACMAT), 2008, pp.\u00a01\u201310.","DOI":"10.1145\/1377836.1377838"},{"key":"ref010","doi-asserted-by":"publisher","DOI":"10.1145\/501978.501980"},{"key":"ref011","doi-asserted-by":"publisher","DOI":"10.1145\/2445566.2445567"},{"issue":"1","key":"ref012","first-page":"459","volume":"13","author":"Frank M.","year":"2012","journal-title":"Journal of Machine Learning Research"},{"key":"ref013","doi-asserted-by":"crossref","unstructured":"L.\u00a0Fuchs and G.\u00a0Pernul, HyDRo \u2013 hybrid development of roles, in: Proceedings of 4th International Conference on Information Systems Security (ICISS), 2008, pp.\u00a0287\u2013302.","DOI":"10.1007\/978-3-540-89862-7_24"},{"key":"ref014","doi-asserted-by":"crossref","unstructured":"N.\u00a0Gal-Oz, Y.\u00a0Gonen, R.\u00a0Yahalom, E.\u00a0Gudes, B.\u00a0Rozenberg and E.\u00a0Shmueli, Mining roles from web application usage patterns, in: Proceedings of 8th International Conference on Trust, Privacy and Security in Digital Business (TrustBus), 2011, pp.\u00a0125\u2013137.","DOI":"10.1007\/978-3-642-22890-2_11"},{"key":"ref015","unstructured":"M.R.\u00a0Garey and D.S.\u00a0Johnson, Computers and Intractability: A Guide to the Theory of NP-Completeness, Freeman, 1979."},{"key":"ref016","doi-asserted-by":"crossref","unstructured":"Q.\u00a0Guo, J.\u00a0Vaidya and V.\u00a0Atluri, The role hierarchy mining problem: discovery of optimal role hierarchies, in: Proceedings of 24th Annual Computer Security Applications Conference (ACSAC), 2008, pp.\u00a0237\u2013246.","DOI":"10.1109\/ACSAC.2008.38"},{"key":"ref017","doi-asserted-by":"crossref","unstructured":"S.\u00a0Hachana, F.\u00a0Cuppens, N.\u00a0Cuppens-Boulahia and J.\u00a0Garcia-Alfaro, Towards automated assistance for mined roles analysis in role mining applications, in: Proceedings of 7th International Conference on Availability, Reliability and Security (ARES), 2012, pp.\u00a0123\u2013132.","DOI":"10.1109\/ARES.2012.61"},{"key":"ref018","doi-asserted-by":"crossref","unstructured":"M.\u00a0Hingankar and S.\u00a0Sural, Towards role mining with restricted user-role assignment, in: Proceedings of 2nd International Conference on Wireless Communication, Vehicular Technology, Information Theory and Aerospace Electronic Systems Technology (Wireless VITAE), 2011, pp.\u00a01\u20135.","DOI":"10.1109\/WIRELESSVITAE.2011.5940855"},{"key":"ref019","doi-asserted-by":"crossref","unstructured":"J.\u00a0Hu, K.M.\u00a0Khan, Y.\u00a0Bai and Y.\u00a0Zhang, Constraint-enhanced role engineering via answer set programming, in: Proceedings of 7th ACM Symposium on Information, Computer and Communications Security (ASIACCS), 2012, pp.\u00a073\u201374.","DOI":"10.1145\/2414456.2414499"},{"key":"ref020","doi-asserted-by":"crossref","unstructured":"H.\u00a0Huang, F.\u00a0Shang, J.\u00a0Liu and H.\u00a0Du, Handling least privilege problem and role mining in RBAC,\n                      Journal of Combinatorial Optimization\n                      (2014), to appear, DOI: 10.1007\/s10878-013-9633-9.","DOI":"10.1007\/s10878-013-9633-9"},{"key":"ref021","doi-asserted-by":"crossref","unstructured":"H.\u00a0Huang, F.\u00a0Shang and J.\u00a0Zhang, Approximation algorithms for minimizing the number of roles and administrative assignments in RBAC, in: Proceedings of 36th Annual IEEE Computer Software and Applications Conference Workshops (COMPSAC), 2012, pp.\u00a0427\u2013432.","DOI":"10.1109\/COMPSACW.2012.81"},{"key":"ref022","doi-asserted-by":"crossref","unstructured":"J.C.\u00a0John, S.\u00a0Sural, V.\u00a0Atluri and J.\u00a0Vaidya, Role mining under role-usage cardinality constraint, in: Proceedings of 27th IFIP TC 11 International Information Security and Privacy Conference (SEC), 2012, pp.\u00a0150\u2013161.","DOI":"10.1007\/978-3-642-30436-1_13"},{"key":"ref023","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2005.1"},{"key":"ref024","doi-asserted-by":"crossref","unstructured":"R.\u00a0Kumar, S.\u00a0Sural and A.\u00a0Gupta, Mining RBAC roles under cardinality constraint, in: Proceedings of 6th International Conference on Information Systems Security (ICISS), 2010, pp.\u00a0171\u2013185.","DOI":"10.1007\/978-3-642-17714-9_13"},{"key":"ref025","doi-asserted-by":"crossref","unstructured":"H.\u00a0Lu, J.\u00a0Vaidya and V.\u00a0Atluri, Optimal Boolean matrix decomposition: application to role engineering, in: Proceedings of 24th IEEE International Conference on Data Engineering (ICDE), 2008, pp.\u00a0297\u2013306.","DOI":"10.1109\/ICDE.2008.4497438"},{"issue":"5","key":"ref026","first-page":"655","volume":"9","author":"Lu H.","year":"2012","journal-title":"IEEE Transactions on Dependable and Secure Computing (TDSC)"},{"key":"ref027","doi-asserted-by":"crossref","unstructured":"X.\u00a0Ma, R.\u00a0Li and Z.\u00a0Lu, Role mining based on weights, in: Proceedings of 15th ACM Symposium on Access Control Models and Technologies (SACMAT), 2010, pp.\u00a065\u201374.","DOI":"10.1145\/1809842.1809854"},{"key":"ref028","doi-asserted-by":"crossref","unstructured":"B.\u00a0Mitra, S.\u00a0Sural, V.\u00a0Atluri and J.\u00a0Vaidya, Toward mining of temporal roles, in: Proceedings of 27th Annual IFIP WG 11.3 Working Conference on Data and Applications Security and Privacy (DBSec), 2013, pp.\u00a065\u201380.","DOI":"10.1007\/978-3-642-39256-6_5"},{"key":"ref029","doi-asserted-by":"crossref","unstructured":"I.\u00a0Molloy, H.\u00a0Chen, T.\u00a0Li, Q.\u00a0Wang, N.\u00a0Li, E.\u00a0Bertino, S.\u00a0Calo and J.\u00a0Lobo, Mining roles with semantic meanings, in: Proceedings of 13th ACM Symposium on Access Control Models and Technologies, 2008, pp.\u00a021\u201330.","DOI":"10.1145\/1377836.1377840"},{"key":"ref030","doi-asserted-by":"publisher","DOI":"10.1145\/1880022.1880030"},{"key":"ref031","doi-asserted-by":"crossref","unstructured":"I.\u00a0Molloy, N.\u00a0Li, T.\u00a0Li, Z.\u00a0Mao, Q.\u00a0Wang and J.\u00a0Lobo, Evaluating role mining algorithms, in: Proceedings of 14th ACM Symposium on Access Control Models and Technologies (SACMAT), 2009, pp.\u00a095\u2013104.","DOI":"10.1145\/1542207.1542224"},{"key":"ref032","doi-asserted-by":"crossref","unstructured":"I.\u00a0Molloy, Y.\u00a0Park and S.\u00a0Chari, Generative models for access control policies: applications to role mining over logs with attribution, in: Proceedings of 17th ACM Symposium on Access Control Models and Technologies (SACMAT), 2012, pp.\u00a045\u201356.","DOI":"10.1145\/2295136.2295145"},{"key":"ref033","doi-asserted-by":"crossref","unstructured":"H.\u00a0Roeckle, G.\u00a0Schimpf and R.\u00a0Weidinger, Process-oriented approach for role-finding to implement role-based security administration in a large industrial organization, in: Proceedings of 5th ACM Workshop on Role-Based Access Control, 2000, pp.\u00a0103\u2013110.","DOI":"10.1145\/344287.344308"},{"key":"ref034","doi-asserted-by":"publisher","DOI":"10.1109\/2.485845"},{"key":"ref035","doi-asserted-by":"crossref","unstructured":"J.\u00a0Vaidya, V.\u00a0Atluri and Q.\u00a0Guo, The role mining problem: finding a minimal descriptive set of roles, in: Proceedings of 12th ACM Symposium on Access Control Models and Technologies (SACMAT), 2007, pp.\u00a0175\u2013184.","DOI":"10.1145\/1266840.1266870"},{"key":"ref036","doi-asserted-by":"publisher","DOI":"10.1145\/1805974.1805983"},{"key":"ref037","doi-asserted-by":"crossref","unstructured":"J.\u00a0Vaidya, V.\u00a0Atluri, Q.\u00a0Guo and H.\u00a0Lu, Role mining in the presence of noise, in: Proceedings of 24th Annual IFIP WG 11.3 Working Conference on Data and Applications Security and Privacy (DBSec), 2010, pp.\u00a097\u2013112.","DOI":"10.1007\/978-3-642-13739-6_7"},{"key":"ref038","doi-asserted-by":"crossref","unstructured":"J.\u00a0Vaidya, V.\u00a0Atluri and J.\u00a0Warner, Role miner: mining roles using subset enumeration, in: Proceedings of 13th ACM Conference on Computer and Communications Security (CCS), 2006, pp.\u00a0144\u2013153.","DOI":"10.1145\/1180405.1180424"},{"key":"ref039","doi-asserted-by":"crossref","unstructured":"N.V.\u00a0Verde, J.\u00a0Vaidya, V.\u00a0Atluri and A.\u00a0Colantonio, Role engineering: from theory to practice, in: Proceedings of 2nd ACM Conference on Data and Application Security and Privacy (CODASPY), 2012, pp.\u00a0181\u2013191.","DOI":"10.1145\/2133601.2133624"},{"key":"ref040","doi-asserted-by":"crossref","unstructured":"Z.\u00a0Xu and S.D.\u00a0Stoller, Algorithms for mining meaningful roles, in: Proceedings of 17th ACM Symposium on Access Control Models and Technologies (SACMAT), 2012, pp.\u00a057\u201366.","DOI":"10.1145\/2295136.2295146"},{"key":"ref041","doi-asserted-by":"crossref","unstructured":"W.\u00a0Zhang, Y.\u00a0Chen, C.\u00a0Gunter, D.\u00a0Liebovitz and B.\u00a0Malin, Evolving role definitions through permission invocation patterns, in: Proceedings of 18th ACM Symposium on Access Control Models and Technologies (SACMAT), 2013, pp.\u00a037\u201348.","DOI":"10.1145\/2462410.2462422"},{"key":"ref042","doi-asserted-by":"crossref","unstructured":"W.\u00a0Zhao, Q.\u00a0Lin, Y.\u00a0Shi and X.\u00a0Fang, Mining the role-oriented process models based on genetic algorithm, in: Proceedings of 3rd International Conference on Advances in Swarm Intelligence (ICSI), 2012, pp.\u00a0398\u2013405.","DOI":"10.1007\/978-3-642-30976-2_48"}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-140512","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-140512","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-140512","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:44:49Z","timestamp":1777495489000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-140512"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,3,15]]},"references-count":42,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2015,3,15]]}},"alternative-id":["10.3233\/JCS-140512"],"URL":"https:\/\/doi.org\/10.3233\/jcs-140512","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,3,15]]}}}