{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,17]],"date-time":"2026-06-17T15:41:19Z","timestamp":1781710879841,"version":"3.54.5"},"reference-count":0,"publisher":"SAGE Publications","issue":"2","license":[{"start":{"date-parts":[[2009,3,24]],"date-time":"2009-03-24T00:00:00Z","timestamp":1237852800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2009,3,24]]},"abstract":"<jats:p>Because of its ease of administration, role-based access control (RBAC) has become the norm to enforcing security in most of today's organizations. For implementing RBAC, it is important to devise a complete and correct set of roles. This task, known as role engineering, has been identified as one of the costliest components in deploying RBAC. A key problem with respect to role engineering is that there is no formal metric for measuring the goodness\/interestingness of the devised set of roles. Recently, Vaidya et al. [26], formally define the role mining problem (RMP) as the problem of discovering an optimal set of roles from existing user permissions, and analyze its theoretical bounds. Essentially, given a user-permission assignment (UPA), the basic RMP is to discover the user-role assignment relation (UA) and role-permission assignment relation (PA) such that the number of roles required is minimum. In this paper, we present another interesting and useful problem, called the edge-RMP, with a different minimality objective. The edge-RMP, requires the discovery of a complete and correct set of roles such that the discovered |UA|+|PA| is the minimum possible. Minimal |UA|+|PA| is a useful metric as it would minimize the administrative burden since less number of assignments need to be managed. Although the basic-RMP and the edge-RMP appear to be related problems, we demonstrate with concrete examples that they are, in fact, independent of each other. We prove that the edge-RMP is an NP-hard problem by reducing the known \u201cvertex cover problem\u201d to the decision version of the edge-RMP. Another important contribution of this paper is to provide a binary integer programming solution to this problem by showing that the edge-RMP can be formulated in that form. As a result, one can directly borrow existing implementation solutions for binary integer programming and guide further research in this direction. We also propose a heuristic solution for large scale problems, and experimentally validate our algorithm.<\/jats:p>","DOI":"10.3233\/jcs-2009-0341","type":"journal-article","created":{"date-parts":[[2016,5,18]],"date-time":"2016-05-18T03:38:33Z","timestamp":1463542713000},"page":"211-235","source":"Crossref","is-referenced-by-count":26,"title":["Edge-RMP: Minimizing administrative assignments for role-based access control"],"prefix":"10.1177","volume":"17","author":[{"given":"Jaideep","family":"Vaidya","sequence":"first","affiliation":[{"name":"MSIS Department, Rutgers University, 180 University Ave, Newark, NJ 07102, USA. E-mails: , , ,"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vijayalakshmi","family":"Atluri","sequence":"additional","affiliation":[{"name":"MSIS Department, Rutgers University, 180 University Ave, Newark, NJ 07102, USA. E-mails: , , ,"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qi","family":"Guo","sequence":"additional","affiliation":[{"name":"MSIS Department, Rutgers University, 180 University Ave, Newark, NJ 07102, USA. E-mails: , , ,"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haibing","family":"Lu","sequence":"additional","affiliation":[{"name":"MSIS Department, Rutgers University, 180 University Ave, Newark, NJ 07102, USA. E-mails: , , ,"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"179","published-online":{"date-parts":[[2009,3,24]]},"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-2009-0341","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-2009-0341","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:44:01Z","timestamp":1777495441000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-2009-0341"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,3,24]]},"references-count":0,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2009,3,24]]}},"alternative-id":["10.3233\/JCS-2009-0341"],"URL":"https:\/\/doi.org\/10.3233\/jcs-2009-0341","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2009,3,24]]}}}