A logical language for expressing authorizations

A logical language for expressing authorizations
复制标题

表达授权的逻辑语言

DOI:
10.1109/secpri.1997.601312
复制
发表时间:
1997
期刊:
Proceedings. 1997 IEEE Symposium on Security and Privacy (Cat. No.97CB36097)
影响因子:
--
通讯作者:
V. S. Subrahmanian
V. S. Subrahmanian
中科院分区:
--
文献类型:
--
作者:
S. Jajodia;P. Samarati;V. S. Subrahmanian

文献摘要

被引文献

相似文献

现有访问控制系统的一个主要缺点是它们都是在开发时考虑了特定的访问控制策略。这意味着所有保护要求(即允许或拒绝的访问)必须根据系统执行的策略来指定。虽然这对于某些需求来说可能是微不足道的,但其他需求的规范可能会变得相当复杂甚至不可能。其原因是单个策略根本无法捕获用户可能需要对不同数据实施的不同保护要求。在本文中,我们向能够支持不同访问控制策略的模型迈出了第一步。我们提出了一种用于授权规范的逻辑语言,这样的模型可以基于该逻辑语言。授权规范语言 (ASL) 允许用户与授权一起指定制定访问控制决策所依据的策略。策略通过强制授权的派生、冲突解决、访问控制和完整性约束检查的规则来表达。我们通过展示有时需要但现有访问控制系统很少支持的不同约束如何用我们的语言表示来说明我们语言的强大功能。
A major drawback of existing access control systems is that they have all been developed with a specific access control policy in mind. This means that all protection requirements (i.e. accesses to be allowed or denied) must be specified in terms of the policy enforced by the system. While this may be trivial for some requirements, specification of other requirements may become quite complex or even impossible. The reason for this is that a single policy simply cannot capture the different protection requirements that users may need to enforce on different data. In this paper, we take a first step towards a model that is able to support different access control policies. We propose a logical language for the specification of authorizations on which such a model can be based. The Authorization Specification Language (ASL) allows users to specify, together with the authorizations, the policy according to which access control decisions are to be made. Policies are expressed by means of rules which enforce the derivation of authorizations, conflict resolution, access control and integrity constraint checking. We illustrate the power of our language by showing how different constraints that are sometimes required, but very seldom supported by existing access control systems, can be represented in our language.