ACM Home Page
Please provide us with feedback. Feedback
Access control by action control
Full text PdfPdf (380 KB)
Source
Symposium on Access Control Models and Technologies archive
Proceedings of the 13th ACM symposium on Access control models and technologies table of contents
Estes Park, CO, USA
SESSION: Obligations table of contents
Pages 143-152  
Year of Publication: 2008
ISBN:978-1-60558-129-3
Author
Steve Barker  King's College London, The Strand, London
Sponsors
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 8,   Downloads (12 Months): 182,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1377836.1377858
What is a DOI?

ABSTRACT

We address the problem of defining access control policies that may be used in the evaluation of requests made by client actors, in the course of e-trading, to perform actions on the resources maintained by an e-collective. An e-collective is a group of agents that may act individually or in conjunction with other agents to satisfy a client's request to act. Our principal contribution to this key problem is to define formally an access control model in terms of which policies may be specified for helping to ensure that only legitimate forms of client actions are performed in the course of engaging in e-trading. We call this model the action control model. In action control, the notion of intentional, empowered, authorized actions, that may be performed individualistically or jointly with other agents, and in a manner that is consistent with a group ethos, is the basis for specifying a set of permissives. A permissive is a generalization of the notion of a permission (as the latter term is usually interpreted in access control). In addition to the formal definition of the action control model, we give examples of action control policy specifications and we describe a candidate implementation and performance measures.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

1
 
2
C. Baral and M. Gelfond. Logic programming and knowledge representation. JLP, 19/20:73--148, 1994.
 
3
 
4
5
6
 
7
D. E. Bell and L. J. LaPadula. Secure computer system: Unified exposition and multics interpretation. MITRE-2997, 1976.
8
9
 
10
The Ciao Prolog System, 2004.
 
11
K. Clark. Negation as failure. In H. Gallaire and J. Minker, editors, Logic and Databases, pages 293--322. Plenum, 1978.
12
 
13
14
15
 
16
17
 
18
T. Miyakawa. The Science of Public Policy. Routledge, 1999.
 
19
OASIS. eXtensible Access Control Markup Language (XACML), 2003. http://www.oasis-open.org/xacml/docs/.
 
20
21
22
23
24
 
25
W. Tolone, R. Gandhi, and G. Ahn. Locale-based access control: placing collaborative authorization decisions in context. In SMC'03, 2003.
 
26
R. Tuomela. Cooperation. Kluwer, 1999.
 
27
 
28