Reachability Analysis for Attributes in ABAC With Group Hierarchy

Reachability Analysis for Attributes in ABAC With Group Hierarchy
复制标题

DOI:
10.1109/tdsc.2022.3145358
复制
发表时间:
2021-01
影响因子:
7.3
通讯作者:
Maanak Gupta;R. Sandhu
Maanak Gupta;R. Sandhu
中科院分区:
计算机科学2区
文献类型:
--
作者:
Maanak Gupta;R. Sandhu

文献摘要

相似文献

基于属性的访问控制(ABAC)模型被广泛用于提供基于用户、资源和其他相关实体的属性的细粒度和适应性授权。基于分组和属性的分层访问控制(HGABAC)模型提出了通过组成员关系继承属性的新概念。GURAG随后被提议在ARBAC97和GURA管理模型的基础上,为HGABAC中的用户属性提供一个管理模型。GURA模型使用管理角色来管理用户属性。GURA模型的可达性问题是,给定一组预定义的管理规则,确定特定用户可以获得哪些属性。这个问题已经在以前的文献中进行了分析。本文研究了基于用户直接分配属性和通过组成员关系继承属性的用户属性可达性问题。我们首先定义了一种受限形式的GURAG,称为rGURAG方案,作为具有不同前提条件的多个实例的状态转换系统,并对每种方案进行了可达性分析。总的来说,我们展示了所有rGURAG方案的PSPACE-complete复杂度。我们进一步提出了多项式时间算法和经验实验评估,以解决rGURAG方案在限制条件下的特殊实例。
Attribute-based access control (ABAC) models are widely used to provide fine-grained and adaptable authorization based on the attributes of users, resources, and other relevant entities. Hierarchical group and attribute based access control (HGABAC) model was recently proposed which introduces the novel notion of attribute inheritance through group membership. GURAG was subsequently proposed to provide an administrative model for user attributes in HGABAC, building upon the ARBAC97 and GURA administrative models. The GURA model uses administrative roles to manage user attributes. The reachability problem for the GURA model is to determine what attributes a particular user can acquire, given a predefined set of administrative rules. This problem has been previously analyzed in the literature. In this article, we study the user attribute reachability problem based on directly assigned attributes of the user and attributes inherited via group memberships. We first define a restricted form of GURAG, called rGURAG scheme, as a state transition system with multiple instances having different preconditions and provide reachability analysis for each of these schemes. In general, we show PSPACE-complete complexity for all rGURAG schemes. We further present polynomial time algorithms with empirical experimental evaluation to solve special instances of rGURAG schemes under restricted conditions.