A logical framework for reasoning about access control models

A logical framework for reasoning about access control models
复制标题

推理访问控制模型的逻辑框架

DOI:
10.1145/373256.373261
复制
发表时间:
2001
期刊:
--
影响因子:
--
通讯作者:
P. Perlasca
P. Perlasca
中科院分区:
--
文献类型:
--
作者:
E. Bertino;B. Catania;E. Ferrari;P. Perlasca

文献摘要

被引文献

相似文献

访问和使用数据的工具和技术的可用性不断提高,使得数据保护的需求更加迫切。此外,新兴的应用程序和数据模型需要更灵活和更具表现力的访问控制模型。这导致了广泛的研究活动,从而定义了各种访问控制模型,这些模型在它们可以支持的访问控制策略方面存在很大差异。因此,需要开发某种工具来推理此类模型的表达能力并在各种建议之间进行比较。在本文中,我们通过提出一个用于推理访问控制模型的正式框架,朝着这个方向迈出了第一步。我们提出的框架基于逻辑形式主义,并且足够通用,可以对任意和强制访问控制策略进行建模。所提出框架的每个实例对应于一个 C-Datalog 程序 [8],根据稳定的模型语义进行解释。在本文中,除了给出我们框架的语法和形式语义之外,我们还展示了其应用的一些示例。
The increased availability of tools and technologies to access and use the data has made more urgent the needs for data protection. Moreover, emerging applications and data models call for more flexible and expressive access control models. This has lead to an extensive research activity that has resulted in the definition of a variety of access control models, that greatly differ with respect to the access control policies they can support. The need thus arises of developing some sort of tools that make it possible to reason about the expressive power of such models and to make a comparison among the various proposals. In this paper we make a first step in this direction by proposing a formal framework for reasoning about access control models. The framework we propose is based on a logical formalism and is general enough to model both discretionary and mandatory access control policies. Each instance of the proposed framework corresponds to a C-Datalog program [8], interpreted according to a stable model semantics. In the paper, besides giving the syntax and the formal semantic of our framework, we show some examples of its application.