{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T10:59:14Z","timestamp":1777805954028,"version":"3.51.4"},"reference-count":31,"publisher":"SAGE Publications","issue":"1","license":[{"start":{"date-parts":[[2015,3,15]],"date-time":"2015-03-15T00:00:00Z","timestamp":1426377600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2015,3,15]]},"abstract":"<jats:p>Role mining is to define a role set to implement the role-based access control (RBAC) system and regarded as one of the most important and costliest implementation phases. While various role mining models have been proposed, we find that user experience\/perception \u2013 one ultimate goal for any information system \u2013 is surprisingly ignored by the existing works. One advantage of RBAC is to support multiple role assignments and allow a user to activate the necessary role to perform the tasks at each session. However, frequent role activating and deactivating can be a tendinous thing from the user perspective. A user-friendly RBAC system is expected to assign few roles to every user. So in this paper we propose to incorporate to the role mining process a user-role assignment constraint that mandates the maximum number of roles each user can have. Under this rationale, we formulate user-oriented role mining as the user role mining problem, where all users have the same maximal role assignments, the personalized role mining problem, where users can have different maximal role assignments, and the approximate versions of the two problems, which tolerate a certain amount of deviation from the complete reconstruction. The extra constraint on the maximal role assignments poses a great challenge to role mining, which in general is already a hard problem. We examine some typical existing role mining methods to see their applicability to our problems. In light of their insufficiency, we present a new algorithm, which is based on a novel dynamic candidate role generation strategy, tailored to our problems. Experiments on benchmark data sets demonstrate the effectiveness of our proposed algorithm.<\/jats:p>","DOI":"10.3233\/jcs-140519","type":"journal-article","created":{"date-parts":[[2016,5,18]],"date-time":"2016-05-18T03:46:52Z","timestamp":1463543212000},"page":"107-129","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":15,"title":["Towards user-oriented RBAC model"],"prefix":"10.1177","volume":"23","author":[{"given":"Haibing","family":"Lu","sequence":"first","affiliation":[{"name":"Santa Clara University, Santa Clara, CA, USA. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuan","family":"Hong","sequence":"additional","affiliation":[{"name":"University at Albany \u2013 SUNY, Albany, NY, USA. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yanjiang","family":"Yang","sequence":"additional","affiliation":[{"name":"Institute for Infocomm Research, Singapore. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lian","family":"Duan","sequence":"additional","affiliation":[{"name":"New Jersey Institute of Technology, Newark, NJ, USA. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nazia","family":"Badar","sequence":"additional","affiliation":[{"name":"Rutgers University, Newark, NJ, USA. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2015,3,15]]},"reference":[{"key":"ref001","doi-asserted-by":"crossref","unstructured":"K.\u00a0Brooks, Migrating to role-based access control, in: ACM Workshop on Role-Based Access Control, 1999, pp.\u00a071\u201381.","DOI":"10.1145\/319171.319178"},{"key":"ref002","doi-asserted-by":"crossref","unstructured":"E.J.\u00a0Coyne, Role engineering, in: RBAC\u201995: Proceedings of the First ACM Workshop on Role-based Access Control, ACM, New York, NY, USA, 1996, p.\u00a04.","DOI":"10.1145\/270152.270159"},{"key":"ref003","doi-asserted-by":"crossref","unstructured":"A.\u00a0Ene, W.\u00a0Horne, N.\u00a0Milosavljevic, P.\u00a0Rao, R.\u00a0Schreiber and R.E.\u00a0Tarjan, Fast exact and heuristic methods for role minimization problems, in: SACMAT\u201908: Proceedings of the 13th ACM Symposium on Access Control Models and Technologies, ACM, New York, NY, USA, 2008, pp.\u00a01\u201310.","DOI":"10.1145\/1377836.1377838"},{"key":"ref004","doi-asserted-by":"crossref","unstructured":"A.\u00a0Ene, W.G.\u00a0Horne, N.\u00a0Milosavljevic, P.\u00a0Rao, R.\u00a0Schreiber and R.E.\u00a0Tarjan, Fast exact and heuristic methods for role minimization problems, in: SACMAT, 2008, pp.\u00a01\u201310.","DOI":"10.1145\/1377836.1377838"},{"key":"ref005","doi-asserted-by":"crossref","unstructured":"E.B.\u00a0Fernandez and J.C.\u00a0Hawkins, Determining role rights from use cases, in: Proceeding of the 2nd ACM Symposium on Access Control Models and Technologies, SACMAT\u201997, 1997.","DOI":"10.1145\/266741.266767"},{"key":"ref006","doi-asserted-by":"crossref","unstructured":"M.\u00a0Frank, D.\u00a0Basin and J.M.\u00a0Buhmann, A class of probabilistic models for role engineering, in: Proceedings of the 15th ACM Conference on Computer and Communications Security, 2008.","DOI":"10.1145\/1455770.1455809"},{"key":"ref007","doi-asserted-by":"crossref","unstructured":"M.\u00a0Frank, A.P.\u00a0Streich, D.\u00a0Basin and J.M.\u00a0Buhmann, A probabilistic approach to hybrid role mining, in: Proceedings of the 16th ACM Conference on Computer and Communications Security, CCS\u201909, ACM, New York, NY, USA, 2009, pp.\u00a0101\u2013111.","DOI":"10.1145\/1653662.1653675"},{"key":"ref008","doi-asserted-by":"crossref","unstructured":"F.\u00a0Geerts, B.\u00a0Goethals and T.\u00a0Mielikainen, Tiling databases, in: Discovery Science, Springer, 2004, pp.\u00a0278\u2013289.","DOI":"10.1007\/978-3-540-30214-8_22"},{"key":"ref009","doi-asserted-by":"crossref","unstructured":"Q.\u00a0Guo, J.\u00a0Vaidya and V.\u00a0Atluri, The role hierarchy mining problem: Discovery of optimal role hierarchies, in: ACSAC, 2008, pp.\u00a0237\u2013246.","DOI":"10.1109\/ACSAC.2008.38"},{"key":"ref010","doi-asserted-by":"crossref","unstructured":"S.\u00a0Hachana, F.\u00a0Cuppens, N.\u00a0Cuppens-Boulahia, V.\u00a0Atluri and S.\u00a0Morucci, Policy mining: A bottom-up approach toward a model based firewall management, in: ICISS, 2013, pp.\u00a0133\u2013147.","DOI":"10.1007\/978-3-642-45204-8_10"},{"key":"ref011","doi-asserted-by":"crossref","unstructured":"A.\u00a0Kern, M.\u00a0Kuhlmann, A.\u00a0Schaad and J.D.\u00a0Moffett, Observations on the role life-cycle in the context of enterprise security management, in: SACMAT, 2002, pp.\u00a043\u201351.","DOI":"10.1145\/507711.507718"},{"key":"ref012","doi-asserted-by":"crossref","unstructured":"M.\u00a0Kuhlmann, D.\u00a0Shohat and G.\u00a0Schimpf, Role mining \u2013 revealing business roles for security administration using data mining technology, in: SACMAT\u201903: Proceedings of the 8th ACM Symposium on Access Control Models and Technologies, ACM, New York, NY, USA, 2003, pp.\u00a0179\u2013186.","DOI":"10.1145\/775433.775435"},{"key":"ref013","doi-asserted-by":"crossref","unstructured":"H.\u00a0Lu, Y.\u00a0Hong, Y.\u00a0Yang, L.\u00a0Duan and N.\u00a0Badar, Towards user-oriented RBAC model, in: DBSec, 2013, pp.\u00a081\u201396.","DOI":"10.1007\/978-3-642-39256-6_6"},{"key":"ref014","doi-asserted-by":"crossref","unstructured":"H.\u00a0Lu, J.\u00a0Vaidya and V.\u00a0Atluri, Optimal Boolean matrix decomposition: Application to role engineering, in: IEEE 24th International Conference on Data Engineering, 2008, pp.\u00a0297\u2013306.","DOI":"10.1109\/ICDE.2008.4497438"},{"key":"ref015","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-130484"},{"key":"ref016","doi-asserted-by":"crossref","unstructured":"H.\u00a0Lu, J.\u00a0Vaidya, V.\u00a0Atluri and Y.\u00a0Hong, Extended Boolean matrix decomposition, in: IEEE International Conference on Data Mining, 2009.","DOI":"10.1109\/ICDM.2009.61"},{"issue":"5","key":"ref017","first-page":"655","volume":"9","author":"Lu H.","year":"2012","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"ref018","doi-asserted-by":"crossref","unstructured":"X.\u00a0Ma, R.\u00a0Li and Z.\u00a0Lu, Role mining based on weights, in: SACMAT, 2010, pp.\u00a065\u201374.","DOI":"10.1145\/1809842.1809854"},{"key":"ref019","doi-asserted-by":"crossref","unstructured":"I.\u00a0Molloy, H.\u00a0Chen, T.\u00a0Li, Q.\u00a0Wang, N.\u00a0Li, E.\u00a0Bertino, S.\u00a0Calo and J.\u00a0Lobo, Mining roles with semantic meanings, in: SACMAT\u201908: Proceedings of the 13th ACM Symposium on Access Control Models and Technologies, ACM, New York, NY, USA, 2008, pp.\u00a021\u201330.","DOI":"10.1145\/1377836.1377840"},{"key":"ref020","doi-asserted-by":"crossref","unstructured":"I.\u00a0Molloy, N.\u00a0Li, T.\u00a0Li, Z.\u00a0Mao, Q.\u00a0Wang and J.\u00a0Lobo, Evaluating role mining algorithms, in: SACMAT\u201909: Proceedings of the 14th ACM Symposium on Access Control Models and Technologies, ACM, New York, NY, USA, 2009, pp.\u00a095\u2013104.","DOI":"10.1145\/1542207.1542224"},{"key":"ref021","doi-asserted-by":"crossref","unstructured":"I.\u00a0Molloy, N.\u00a0Li, Y.A.\u00a0Qi, J.\u00a0Lobo and L.\u00a0Dickens, Mining roles with noisy data, in: Proceeding of the 15th ACM Symposium on Access Control Models and Technologies, SACMAT\u201910, ACM, New York, NY, USA, 2010, pp.\u00a045\u201354.","DOI":"10.1145\/1809842.1809852"},{"key":"ref022","doi-asserted-by":"crossref","unstructured":"G.\u00a0Neumann and M.\u00a0Strembeck, A scenario-driven role engineering process for functional RBAC roles, in: SACMAT, 2002, pp.\u00a033\u201342.","DOI":"10.1145\/507711.507717"},{"key":"ref023","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2008.53"},{"key":"ref024","doi-asserted-by":"crossref","unstructured":"H.\u00a0Roeckle, G.\u00a0Schimpf and R.\u00a0Weidinger, Process-oriented approach for role-finding to implement role-based security administration in a large industrial organization, in: ACM Workshop on Role-Based Access Control, 2000, pp.\u00a0103\u2013110.","DOI":"10.1145\/344287.344308"},{"key":"ref025","doi-asserted-by":"crossref","unstructured":"J.\u00a0Schlegelmilch and U.\u00a0Steffens, Role mining with ORCA, in: SACMAT\u201905: Proceedings of the 10th ACM Symposium on Access Control Models and Technologies, 2005, pp.\u00a0168\u2013176.","DOI":"10.1145\/1063979.1064008"},{"key":"ref026","doi-asserted-by":"publisher","DOI":"10.1007\/s13174-011-0035-x"},{"key":"ref027","doi-asserted-by":"crossref","unstructured":"A.P.\u00a0Streich, M.\u00a0Frank, D.\u00a0Basin and J.M.\u00a0Buhmann, Multi-assignment clustering for Boolean data, in: Proceedings of the 26th Annual International Conference on Machine Learning, ICML\u201909, ACM, New York, NY, USA, 2009, pp.\u00a0969\u2013976.","DOI":"10.1145\/1553374.1553498"},{"key":"ref028","doi-asserted-by":"crossref","unstructured":"J.\u00a0Vaidya, V.\u00a0Atluri and Q.\u00a0Guo, The role mining problem: finding a minimal descriptive set of roles, in: SACMAT, 2007, pp.\u00a0175\u2013184.","DOI":"10.1145\/1266840.1266870"},{"key":"ref029","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2009-0341"},{"key":"ref030","doi-asserted-by":"crossref","unstructured":"J.\u00a0Vaidya, V.\u00a0Atluri, Q.\u00a0Guo and H.\u00a0Lu, Role mining in the presence of noise, in: DBSec, 2010, pp.\u00a097\u2013112.","DOI":"10.1007\/978-3-642-13739-6_7"},{"key":"ref031","doi-asserted-by":"crossref","unstructured":"J.\u00a0Vaidya, V.\u00a0Atluri and J.\u00a0Warner, Roleminer: mining roles using subset enumeration, in: The 13th ACM Conference on Computer and Communications Security, 2006, pp.\u00a0144\u2013153.","DOI":"10.1145\/1180405.1180424"}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-140519","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-140519","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-140519","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:44:50Z","timestamp":1777495490000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-140519"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,3,15]]},"references-count":31,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2015,3,15]]}},"alternative-id":["10.3233\/JCS-140519"],"URL":"https:\/\/doi.org\/10.3233\/jcs-140519","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,3,15]]}}}