Role-Based Access Control for the Large Hadron Collider at CERN

  • Ilia Yastrebov 1. European Organization for Nuclear Research Switzerland, 1211 Geneva 23, and 2. Joint Institure for Nuclear Research Russia, 141980 Dubna, 6 Jolio-Curie E-mail:


Large Hadron Collider (LHC) is the largest scientific instrument ever created. It was built with the intention of testing the most extreme conditions of the matter. Taking into account the significant dangers of LHC operations, European Organization for Nuclear Research (CERN) has developed multi-pronged approach for machine safety, including access control system. This system is based on rolebased access control (RBAC) concept. It was designed to protect from accidental and unauthorized access to the LHC and injector equipment. This paper introduces the new model of the role-based access control developed at CERN and gives detailed mathematical description of it. We propose a new technique called dynamic authorization that allows deploying RBAC gradually in the large systems. Moreover, we show how the protection for the very large distributed equipment control system may be implemented in efficient way. This paper also describes motivation of the project, requirements and overview of the main components: authentication and authorization.


Software development, role-based access control, information security, equipment protection