| Policy algebras for access control the predicate case |
| Full text |
Pdf
(257 KB)
|
| Source
|
Conference on Computer and Communications Security
archive
Proceedings of the 9th ACM conference on Computer and communications security
table of contents
Washington, DC, USA
SESSION: Authentication and authorization
table of contents
Pages: 171 - 180
Year of Publication: 2002
ISBN:1-58113-612-9
|
|
Authors
|
|
| Sponsors |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 9, Downloads (12 Months): 44, Citation Count: 4
|
|
|
ABSTRACT
This paper deals with the algebra used to compose access control policies of collaborating organizations. To maintain a conceptual coherence and to have a common basis for comparison, we seek a framework that can be viewed at different levels of abstraction. In [21, 22], we presented a propositional version of the algebra that can support algebraic manipulations of uninterpreted policies. This paper extends the algebra to many sorted first order predicate case. The predicate version can be used to reason about first order properties of security policies from their components. We show how to compose and reason about security properties such as those used in role based access control models usually specified using second order (set) quantifiers in languages (see RCL2000 [1]). We also show how different application specific notions of consistency and completeness can be formulated as sentences in our many sorted first order logic and propose a Hoare calculus to reason about them.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
|
| |
2
|
B. Alpern and F. B. Schneider. Defining liveness. Information Processing Letters, 21(4):181--185, October 1985.
|
| |
3
|
B. Alpern and F. B. Schneider. Recognizing safety and liveness. Distributed Computing, 2:117--126, 1987.
|
| |
4
|
|
| |
5
|
J. Barwise and S. Feffermann. Model Theoretic Logics. Springer-Verlag, 1985.
|
 |
6
|
|
| |
7
|
S. A. Cook. Soundness and completeness of an axiom system for program verfication. SIAM Journal on Computing, pages 79--90, 1978.
|
| |
8
|
J. Dobson and J. McDermid. A framework for expressing models of security policy. In Proceedings of IEEE Symposium on Security and Privacy, pages 229--239, May 1989.
|
| |
9
|
H. B. Enderton. Mathematical Introduction to Logic. Harcourt Academic Press, 2001.
|
| |
10
|
|
| |
11
|
|
 |
12
|
|
 |
13
|
|
| |
14
|
|
| |
15
|
|
| |
16
|
|
| |
17
|
J. McLean. Algebra of security. In Proc. IEEE Symp. on Security and Privacy, pages 2--7, Oakland, CA, May 1998.
|
| |
18
|
|
 |
19
|
|
| |
20
|
|
 |
21
|
|
 |
22
|
|
CITED BY 4
|
|
|
|
|
Radha Jagadeesan , Will Marrero , Corin Pitcher , Vijay Saraswat, Timed constraint programming: a declarative approach to usage control, Proceedings of the 7th ACM SIGPLAN international conference on Principles and practice of declarative programming, p.164-175, July 11-13, 2005, Lisbon, Portugal
|
|
|
|
|
|
Ninghui Li , Qihua Wang , Wahbeh Qardaji , Elisa Bertino , Prathima Rao , Jorge Lobo , Dan Lin, Access control policy combining: theory meets practice, Proceedings of the 14th ACM symposium on Access control models and technologies, June 03-05, 2009, Stresa, Italy
|
|