Modeling adaptive access control policies using answer set programming
Modeling adaptive access control policies using answer set programming
复制标题
使用答案集编程对自适应访问控制策略进行建模
DOI:
10.1016/j.jisa.2018.10.007
复制
发表时间:
2019
影响因子:
5.6
通讯作者:
Namin, Akbar Siami
中科院分区:
文献类型:
--
作者:
Sartoli, Sara;Namin, Akbar Siami
Many of the existing management platforms such as pervasive computing systems implement policies that depend on dynamic operational environment changes. Existing formal approaches for automatically enforcing access control policies are primarily expressed in conventional logic programming, also known as monotonic logics, e.g., First Order Logic (FOL). The major issue with monotonic logics is that they are not devised to invalidate initial believes in the light of further observations. This limitation makes these traditional logical approaches less suitable for modeling and analyzing context-aware access control policies, where exceptional policies are introduced incrementally and adaptively during runtime. The inability to invalidate initial policies when an exception needs to be enforced might result in inconsistencies and violations that need to be resolved manually by human entities. To address the problems with conventional logical approaches and more importantly prevent such inconsistencies, this paper presents a non-monotonic logic-based reasoning scheme for modeling and analyzing adaptive access control policies. In the proposed formalism, unavailable context data and incomplete access control policies can be explicitly expressed. To do so, the paper distinguishes three kinds of policies: default, context-dependent and exception policies. The proposed formalism is based on Answer Set Programming (ASP), a non-monotonic logic programming language that allows elegant representation of unavailability of context data in adaptive systems. We devise non-monotonic policy inference rules such that, when exception policies are defined, they take precedence over default and context-dependent policies automatically. The results of two case studies are reported to demonstrate the feasibility of the proposed policy representation scheme compared to the Organizational-Based Access Control (OrBAC) model.
登录
查看更多内容
DOI:
10.1145/3243734.3278489
发表时间:
2018-10
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
Jianjun Zheng;A. Namin
通讯作者:
Jianjun Zheng;A. Namin
DOI:
--
发表时间:
2007
期刊:
ICS@SYNASC
影响因子:
--
作者:
F. Cuppens;N. Cuppens;Meriam Ben
通讯作者:
Meriam Ben
DOI:
--
发表时间:
2015
期刊:
ACM Symposium on Access Control Models and Technologies
影响因子:
--
作者:
J. Crampton;C. Morisset;Nicola Zannone
通讯作者:
Nicola Zannone
DOI:
--
发表时间:
2015
期刊:
International Conference on New Technologies, Mobility and Security
影响因子:
--
作者:
D. Ayed;Marie;Cyrille Martins
通讯作者:
Cyrille Martins
DOI:
--
发表时间:
2012
期刊:
IEEE International Requirements Engineering Conference
影响因子:
--
作者:
Elda Paja;F. Dalpiaz;Mauro Poggianella;Pierluigi Roberti;P. Giorgini
通讯作者:
P. Giorgini