Conflict Detection and Resolution in Access Control Policy Specifications
Conflict Detection and Resolution in Access Control Policy Specifications
复制标题
访问控制策略规范中的冲突检测和解决
DOI:
10.1007/3-540-45931-6_16
复制
发表时间:
2002
期刊:
影响因子:
--
通讯作者:
F. Parisi
中科院分区:
文献类型:
--
作者:
M. Koch;L. Mancini;F. Parisi
Graph-based specification formalisms for Access Control (AC) policies combine the advantages of an intuitive visual framework with a rigorous semantical foundation. A security policy framework specifies a set of (constructive) rules to build the system states and sets of positive and negative (declarative) constraints to specify wanted and unwanted substates. Models for AC (e.g. role-based, lattice-based or an access control list) have been specified in this framework elsewhere. Here we address the problem of inconsistent policies within this framework. Using formal properties of graph transformations, we can systematically detect inconsistencies between constraints, between rules and between a rule and a constraint and lay the foundation for their resolutions.