Role-Based Access Control (RBAC) models have emerged as a leading access control approach for today’s information systems. Hybrid role hierarchies introduced in the Generalized Temporal RBAC model have shown to be very desirable for capturing fine-grained access control semantics. However, its administration can become significantly complex. Efficient techniques are needed to administer such hierarchies to support the development of high performance access control systems. In this paper, we present two approaches to implementing a hybrid role hierarchy in the context of the GTRBAC model and analyze and compare their complexities.
Suroop Mohan Chandran, James B. D. Joshi