Privilege Administration for the Role Graph Model

The role graph model for role-based access control has been introduced in a number of previous papers. In these previous presentations of the role graph model, it is assumed that when privilege p is present in a role, all privileges that might be implied by p are also present in the role. This paper gives revised algorithms to ensure that this is done, using a model for implication of permissions originally developed for object-oriented databases.