ACM Home Page
Please provide us with feedback. Feedback
Formal model and policy specification of usage control
Full text PdfPdf (291 KB)
Source ACM Transactions on Information and System Security (TISSEC) archive
Volume 8 ,  Issue 4  (November 2005) table of contents
Pages: 351 - 387  
Year of Publication: 2005
ISSN:1094-9224
Authors
Xinwen Zhang  George Mason University, Fairfax, VA
Francesco Parisi-Presicce  George Mason University, Fairfax, VA
Ravi Sandhu  George Mason University, Fairfax, VA
Jaehong Park  Eastern Michigan University, Ypsilanti, MI
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 25,   Downloads (12 Months): 187,   Citation Count: 13
Additional Information:

abstract   references   cited by   index terms   review   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1108906.1108908
What is a DOI?

ABSTRACT

The recent usage control model (UCON) is a foundation for next-generation access control models with distinguishing properties of decision continuity and attribute mutability. A usage control decision is determined by combining authorizations, obligations, and conditions, presented as UCONABC core models by Park and Sandhu. Based on these core aspects, we develop a formal model and logical specification of UCON with an extension of Lamport's temporal logic of actions (TLA). The building blocks of this model include: (1) a set of sequences of system states based on the attributes of subjects, objects, and the system, (2) authorization predicates based on subject and object attributes, (3) usage control actions to update attributes and accessing status of a usage process, (4) obligation actions, and (5) condition predicates based on system attributes. A usage control policy is defined as a set of temporal logic formulas that are satisfied as the system state changes. A fixed set of scheme rules is defined to specify general UCON policies with the properties of soundness and completeness. We show the flexibility and expressive capability of this formal model by specifying the core models of UCON and some applications.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
Bell, D. E. and LaPadula, L. J. 1975. Secure computer systems: Mathematical foundations and model. Mitre Corp. Report No.M74-244, Bedford, MA.
2
 
3
4
5
 
6
 
7
Bettini, C., Jajodia, S., Wang, X. S., and Wijesekera, D. 2002b. Provisions and obligations in policy management and security applications. In Proceedings of the 28th VLDB Conference.
 
8
Brewer, D. and Nash, M. 1988. The chinese wall security policy. In Proceedings of the IEEE Symposium on Research in Security and Privacy.
 
9
 
10
11
12
13
 
14
15
16
 
17
18
 
19
20
 
21
Park, J., Zhang, X., and Sandhu, R. 2004. Arrtibute mutability in usage control. In Proceedings of the Proceedings of 18th Annual IFIP WG 11.3 Working Conference on Data and Applications Security.
 
22
 
23
Sandhu, R. and Park, J. 2003. Usage control: A vision for next generation access control. In Proceedings of the Second International Workshop on Mathematical Methods, Models and Architectures for Computer Networks Security.
 
24
25
 
26

CITED BY  13


REVIEW

"Andre C. M. Marien : Reviewer"

This is the latest in a series of papers about user control models (UCON), which provide a basis for next-generation access control systems. Access control in current-generation systems is static. Authorization and control are based on immutable a  more...

Collaborative Colleagues:
Xinwen Zhang: colleagues
Francesco Parisi-Presicce: colleagues
Ravi Sandhu: colleagues
Jaehong Park: colleagues