Conflict Detection and Resolution in Access Control Policy Specifications

Conflict Detection and Resolution in Access Control Policy Specifications
复制标题

访问控制策略规范中的冲突检测和解决

DOI:
10.1007/3-540-45931-6_16
复制
发表时间:
2002
期刊:
Theor. Comput. Sci.
影响因子:
--
通讯作者:
F. Parisi
F. Parisi
中科院分区:
--
文献类型:
--
作者:
M. Koch;L. Mancini;F. Parisi

文献摘要

被引文献

相似文献

访问控制(AC)策略的基于图的规范形式联合收割机结合了直观的可视化框架的优点和严格的语义基础。安全策略框架指定一组(构造性)规则来构建系统状态,并指定一组积极和消极(声明性)约束来指定想要的和不想要的子状态。AC的模型(例如,基于角色的,基于网格的或访问控制列表)已在此框架的其他地方指定。在这里,我们解决这个框架内的政策不一致的问题。利用图变换的形式化性质,我们可以系统地检测约束之间、规则之间以及规则与约束之间的不一致性,并为其解决奠定基础。
Graph-based specification formalisms for Access Control (AC) policies combine the advantages of an intuitive visual framework with a rigorous semantical foundation. A security policy framework specifies a set of (constructive) rules to build the system states and sets of positive and negative (declarative) constraints to specify wanted and unwanted substates. Models for AC (e.g. role-based, lattice-based or an access control list) have been specified in this framework elsewhere. Here we address the problem of inconsistent policies within this framework. Using formal properties of graph transformations, we can systematically detect inconsistencies between constraints, between rules and between a rule and a constraint and lay the foundation for their resolutions.