Rick Kuhn
- Co-authored Role-Based Access Controls (1992) with David Ferraiolo
- Contributed to the NIST RBAC model behind ANSI INCITS 359
- Long-running research on access control assurance and testing
Bio
Rick Kuhn co-authored the 1992 NIST paper on role-based access control with David Ferraiolo and has worked on the model, its formalization, and its assurance ever since, alongside research on combinatorial testing.
Profile built from public NIST and standards records.
Where their work shows up
The testing side of this work matters more than it sounds. An access-control policy that cannot be verified is a policy nobody can safely change, which is why role explosion and stale entitlements outlive the people who created them. See mover entitlement accumulation, RBAC to ReBAC, and what is IGA.
Related on Start with Identity
- BlogA loose PHP comparison let attackers sign in as WordPress admin through SAML
Two unauthenticated bypasses in the miniOrange SAML 2.0 Single Sign On plugin, CVE-2026-61979 and CVE-2026-15981, treat OpenSSL's error return as a valid signat
- BlogAgent identity just got a protocol, which is the easy half
Okta shipped Agent SSO and got Cross App Access adopted into MCP the same month a GitHub issue was shown to reach CI secrets in Claude Code and Gemini CLI. The
- BlogEMVCo drafts one credential standard so merchants stop building per-wallet integrations
EMVCo published a draft framework for verifiable digital credentials in card-based payments, aimed at giving merchants one consistent data structure to authenti
- ExpertCo-author of the Needham-Schroeder protocol
Michael D. Schroeder co-authored two of the foundational papers in this field within three years of each other: the 1975 design-principles paper with Jerome Sal
- ExpertCo-author of the NIST RBAC model
David Ferraiolo co-authored "Role-Based Access Controls" with Rick Kuhn, presented at the 15th National Computer Security Conference in October 1992. The NIST m
- ExpertDirector, CyLab; Professor, Carnegie Mellon University
Lorrie Faith Cranor directs CyLab at Carnegie Mellon and the CyLab Usable Privacy and Security Laboratory, founded the SOUPS symposium, and co-edited Security a