Sebastian Groll

dblp:217/2804 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
5since 2021 · last 2026
0009-0007-1097-4967ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 2 first-author · 5 since 2021
YearPublicationVenuePosition
2026 Formalizing Access Requests in IAM: Beyond Roles and Permissions
Alexander Puchta, Sebastian Groll, Günther Pernul
DBSec2
2024 A Framework for Managing Separation of Duty Policies
abstract
Separation of Duty (SoD) is a fundamental principle in information security. Especially large and highly regulated companies have to manage a huge number of SoD policies. These policies need to be maintained in an ongoing effort in order to remain accurate and compliant with regulatory requirements. In this work we develop a framework for managing SoD policies that pays particular attention to policy comprehensibility. We conducted seven semi-structured interviews with SoD practitioners from large organizations in order to understand the requirements for managing and maintaining SoD policies. Drawing from the obtained insights, we developed a framework, which includes the relevant stakeholders and tasks, as well as a policy structure that aims to simplify policy maintenance. We anchor the proposed policy structure in a generic IAM data model to ensure compatibility and flexibility with other IAM models. We then show exemplary how our approach can be enforced within Role-Based Access Control. Finally, we evaluate the proposed framework with a real-world IAM data set provided by a large finance company.
Sebastian Groll, Sascha Kern, Ludwig Fuchs, Günther Pernul
ARES1
2022 Optimization of Access Control Policies
abstract
Organizations undertake complex and costly projects to model high-quality Access Control Policies (ACPs). Once built, these policies must be maintained and managed in an ongoing process to keep their quality high. Insufficient maintenance leads to inaccurate authorization decisions and increases the policies’ administrative effort and susceptibility to errors. While the initial modeling of ACPs has received significant research interest, their optimization is not yet covered as broadly. This work provides a theoretical foundation for ACP quality and its optimization. Furthermore, it analyzes how existing research addresses optimization of ACPs with regard to six crucial optimization dimensions. It presents a structured literature survey tracing these optimization dimensions, the contributed research artifact and data requirements. Building on this literature catalogue, this work elaborates on inaccuracies for user permission assignments, data availability, minimal perturbation and recommendation-based optimization.
Sascha Kern, Thomas Baumer, Sebastian Groll, Ludwig Fuchs, Günther Pernul
J. Inf. Secur. Appl.3
2021 Leveraging Dynamic Information for Identity and Access Management: An Extension of Current Enterprise IAM Architecture
Alexander Puchta, Sebastian Groll, Günther Pernul
ICISSP2
2021 Monitoring Access Reviews by Crowd Labelling
Sebastian Groll, Sascha Kern, Ludwig Fuchs, Günther Pernul
TrustBus1
2020 Towards a user-centric IAM entitlement shop - Learnings from the e-commerce
abstract
Nowadays, the use of identity and access management systems is the norm in large organizations. Therefore, great efforts are made in science and practice to ensure that these systems will cope with their tasks in the future. However, from a scientific point of view, an important part of the systems has been neglected so far: the user who uses the systems for ordering software or authorizations daily. Therefore, this paper first examines through a survey the challenges these users face and then presents opportunities on how these challenges can be solved. For this, concepts from e-commerce are used, as there are various mechanisms which are already studied both in science and practice.
Markus Hornsteiner, Sebastian Groll, Alexander Puchta
SIN2
2019 Attribute quality management for dynamic identity and access management
Michael Kunz, Alexander Puchta, Sebastian Groll, Ludwig Fuchs, Günther Pernul
J. Inf. Secur. Appl.3
2018 Measuring Identity and Access Management Performance - An Expert Survey on Possible Performance Indicators
Matthias Hummer, Sebastian Groll, Michael Kunz, Ludwig Fuchs, Günther Pernul
ICISSP2