{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:00:50Z","timestamp":1777806050595,"version":"3.51.4"},"reference-count":43,"publisher":"SAGE Publications","issue":"4","license":[{"start":{"date-parts":[[2018,6,13]],"date-time":"2018-06-13T00:00:00Z","timestamp":1528848000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2018,7,10]]},"abstract":"<jats:p>Temporal role-based access control models support the specification and enforcement of several temporal constraints on role enabling, role activation, and temporal role hierarchies among others. In this paper, we define three mappings that preserve the solutions to a class of policy problems: they map security analysis problems in presence of static temporal role hierarchies to problems without them. We show how our mappings can be used to extend the capabilities of a tool for the analysis of administrative temporal role-based access control policies to reason in presence of temporal role hierarchies. We carried out an experimental evaluation with a prototype implementation, which highlighted that one of the proposed mappings behaves better than the other two. To the best of our knowledge, ours is the first tool capable of reasoning with (static) temporal role hierarchies.<\/jats:p>","DOI":"10.3233\/jcs-15756","type":"journal-article","created":{"date-parts":[[2018,6,15]],"date-time":"2018-06-15T13:34:34Z","timestamp":1529069674000},"page":"423-458","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":3,"title":["Automated and efficient analysis of\u00a0administrative temporal RBAC policies with role hierarchies"],"prefix":"10.1177","volume":"26","author":[{"given":"Silvio","family":"Ranise","sequence":"first","affiliation":[{"name":"Security &\u00a0Trust, FBK-Irst, Trento, Italy. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anh","family":"Truong","sequence":"additional","affiliation":[{"name":"Security &\u00a0Trust, FBK-Irst, Trento, Italy. E-mail:\u00a0"},{"name":"DISI, University of Trento, Italy"},{"name":"Ho Chi Minh City University of Technology (HCMUT), Vietnam. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Luca","family":"Vigan\u00f2","sequence":"additional","affiliation":[{"name":"Department of Informatics, King\u2019s College London, United Kingdom. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2018,6,13]]},"reference":[{"key":"ref001","doi-asserted-by":"crossref","unstructured":"F.\u00a0Alberti, A.\u00a0Armando and S.\u00a0Ranise, Efficient symbolic automated analysis of administrative role based access control policies, in: ASIACCS, ACM, 2011.","DOI":"10.1145\/1966913.1966935"},{"key":"ref002","doi-asserted-by":"publisher","DOI":"10.1016\/0304-3975(94)90010-8"},{"key":"ref003","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-1996-42-303"},{"key":"ref004","doi-asserted-by":"crossref","unstructured":"P.\u00a0Amthor, W.E.\u00a0K\u00fchnhauser and A.\u00a0P\u00f6lck, Heuristic safety analysis of access control models, in: Proceedings of the 18th ACM Symposium on Access Control Models and Technologies, SACMAT \u201913, ACM, New York, 2013, pp.\u00a0137\u2013148. doi:10.1145\/2462410.2462413.","DOI":"10.1145\/2462410.2462413"},{"key":"ref005","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.01.002"},{"key":"ref006","doi-asserted-by":"crossref","unstructured":"A.\u00a0Armando and S.\u00a0Ranise, Automated symbolic analysis of ARBAC policies, in: 6th STM Workshop, LNCS, Vol.\u00a06710, Springer, 2010, pp.\u00a017\u201333.","DOI":"10.1007\/978-3-642-22444-7_2"},{"key":"ref007","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2012-0461"},{"key":"ref008","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2006.117"},{"key":"ref009","doi-asserted-by":"publisher","DOI":"10.1145\/501978.501979"},{"key":"ref010","doi-asserted-by":"crossref","unstructured":"S.\u00a0Calzavara, A.\u00a0Rabitti and M.\u00a0Bugliesi, Compositional typed analysis of ARBAC policies, in: Proceedings of the 28th Computer Security Foundations Symposium (CSF), IEEE, 2015, pp.\u00a033\u201345.","DOI":"10.1109\/CSF.2015.10"},{"key":"ref011","doi-asserted-by":"crossref","unstructured":"J.\u00a0Crampton, Understanding and developing role-based administrative models, in: CCS, ACM, 2005.","DOI":"10.1145\/1102120.1102143"},{"key":"ref012","unstructured":"B.A.\u00a0Davey and H.A.\u00a0Priestley, Introduction to Lattices and Orders, 2nd edn, Cambridge University Press, 1991."},{"issue":"2","key":"ref013","first-page":"94","volume":"3","author":"De Capitani di Vimercati S.","year":"2007","journal-title":"International Journal of Computational Science and Engineering (IJCSE)"},{"key":"ref014","unstructured":"H.B.\u00a0Enderton, A Mathematical Introduction to Logic, Academic Press, 1972."},{"key":"ref015","doi-asserted-by":"crossref","unstructured":"A.L.\u00a0Ferrara, P.\u00a0Madhusudan and G.\u00a0Parlato, Policy analysis for self-administrated role-based access control, in: TACAS, Springer, 2013.","DOI":"10.1007\/978-3-642-36742-7_30"},{"key":"ref016","doi-asserted-by":"crossref","unstructured":"M.I.\u00a0Gofman, R.\u00a0Luo, A.C.\u00a0Solomon, Y.\u00a0Zhang, P.\u00a0Yang and S.D.\u00a0Stoller, RBAC-PAT: A policy analysis tool for role based access control, in: TACAS, LNCS, Vol.\u00a05505, Springer, 2009, pp.\u00a046\u201349.","DOI":"10.1007\/978-3-642-00768-2_4"},{"key":"ref017","doi-asserted-by":"publisher","DOI":"10.1145\/360303.360333"},{"key":"ref018","doi-asserted-by":"crossref","unstructured":"K.\u00a0Jayaraman, V.\u00a0Ganesh, M.\u00a0Tripunitara, M.\u00a0Rinard and S.\u00a0Chapin, Automatic error finding for access-control policies, in: CCS, ACM, 2011.","DOI":"10.1145\/2046707.2046727"},{"key":"ref019","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.08.001"},{"issue":"1","key":"ref020","first-page":"4","volume":"7","author":"Joshi J.B.D.","year":"2005","journal-title":"IEEE TKDE"},{"key":"ref021","doi-asserted-by":"crossref","unstructured":"M.\u00a0Koch, L.V.\u00a0Mancini and F.\u00a0Parisi-Presicce, Decidability of safety in graph-based models for access control, in: ESORICS, LNCS, Vol.\u00a02502, 2002, pp.\u00a0229\u2013244.","DOI":"10.1007\/3-540-45853-0_14"},{"key":"ref022","doi-asserted-by":"crossref","unstructured":"N.\u00a0Li and Z.\u00a0Mao, Administration in role based access control, in: ASIACCS, ACM, 2007.","DOI":"10.1145\/1229285.1229305"},{"key":"ref023","doi-asserted-by":"crossref","unstructured":"N.\u00a0Li and M.V.\u00a0Tripunitara, Security analysis in role-based access control, in: Proceedings of ACM Symposium on Access Control Models and Technologies, ACM, 2004, pp.\u00a0126\u2013135.","DOI":"10.1145\/990036.990058"},{"key":"ref024","doi-asserted-by":"publisher","DOI":"10.1145\/1187441.1187442"},{"key":"ref025","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2010.09.002"},{"key":"ref026","doi-asserted-by":"publisher","DOI":"10.1007\/s10817-009-9161-6"},{"issue":"1","key":"ref027","first-page":"24","volume":"42","author":"Ranise S.","year":"2013","journal-title":"FMSD"},{"key":"ref028","doi-asserted-by":"crossref","unstructured":"S.\u00a0Ranise and A.\u00a0Truong, Incremental analysis of evolving administrative role based access control policies, in: DBSec, Springer, 2014, pp.\u00a0206\u2013275.","DOI":"10.1007\/978-3-662-43936-4_17"},{"key":"ref029","doi-asserted-by":"crossref","unstructured":"S.\u00a0Ranise, A.\u00a0Truong and A.\u00a0Armando, Scalable and precise automated analysis of administrative temporal role-based access control, in: SACMAT, ACM, 2014.","DOI":"10.1145\/2613087.2613102"},{"key":"ref030","doi-asserted-by":"crossref","unstructured":"S.\u00a0Ranise, A.\u00a0Truong and L.\u00a0Vigan\u00f2, Automated analysis of RBAC policies with temporal constraints and static role hierarchies, in: Proceedings of the 14th Edition of the Computer Security Track at the 30th ACM Symposium on Applied Computing (SECSAC), ACM, 2015.","DOI":"10.1145\/2695664.2695787"},{"key":"ref031","doi-asserted-by":"crossref","unstructured":"S.\u00a0Ranise, T.A.\u00a0Truong and A.\u00a0Armando, Boosting model checking to analyse large ARBAC policies, in: 8th STM Workshop, LNCS, Vol.\u00a07783, Springer, 2012, pp.\u00a0273\u2013288.","DOI":"10.1007\/978-3-642-38004-4_18"},{"key":"ref032","doi-asserted-by":"publisher","DOI":"10.1145\/300830.300839"},{"key":"ref033","doi-asserted-by":"publisher","DOI":"10.1109\/2.485845"},{"key":"ref034","unstructured":"A.\u00a0Sasturkar, P.\u00a0Yang, S.D.\u00a0Stoller and C.\u00a0Ramakrishnan, Policy analysis for administrative role based access control, in: CSF, IEEE, 2006."},{"key":"ref035","doi-asserted-by":"crossref","unstructured":"J.\u00a0Shahen, J.\u00a0Niu and M.\u00a0Tripunitara, Mohawk+T: Efficient analysis of administrative temporal role-based access control (ATRBAC) policies, in: Proceedings of the 20th ACM Symposium on Access Control Models and Technologies, SACMAT \u201915, ACM, New York, 2015, pp.\u00a015\u201326. doi:10.1145\/2752952.2752966.","DOI":"10.1145\/2752952.2752966"},{"key":"ref036","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.07.005"},{"key":"ref037","first-page":"1","volume":"1","author":"Soshi M.","year":"2004","journal-title":"IEICE-TF"},{"key":"ref038","doi-asserted-by":"crossref","unstructured":"S.D.\u00a0Stoller, P.\u00a0Yang, C.\u00a0Ramakrishnan and M.I.\u00a0Gofman, Efficient policy analysis for administrative role based access control, in: CCS, ACM, 2007.","DOI":"10.1145\/1315245.1315300"},{"key":"ref039","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2007-15202"},{"key":"ref040","doi-asserted-by":"crossref","unstructured":"E.\u00a0Uzun, V.\u00a0Atluri, S.\u00a0Sural, J.\u00a0Vaidya, G.\u00a0Parlato and A.L.\u00a0Ferrara, Analyzing temporal role based access control models, in: SACMAT, ACM, 2012.","DOI":"10.1145\/2295136.2295169"},{"key":"ref041","doi-asserted-by":"crossref","unstructured":"E.\u00a0Uzun, V.\u00a0Atluri, J.\u00a0Vaidya and S.\u00a0Sural, Analysis of TRBAC with dynamic temporal role hierarchies, in: DBSec XXVII, LNCS, Vol.\u00a07964, 2013, pp.\u00a0297\u2013304.","DOI":"10.1007\/978-3-642-39256-6_22"},{"key":"ref042","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-140510"},{"key":"ref043","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-140511"}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-15756","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-15756","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-15756","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:12Z","timestamp":1777495512000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-15756"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,6,13]]},"references-count":43,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2018,7,10]]}},"alternative-id":["10.3233\/JCS-15756"],"URL":"https:\/\/doi.org\/10.3233\/jcs-15756","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,6,13]]}}}