Security Analysis of Relationship-Based Access Control Policies
Security Analysis of Relationship-Based Access Control Policies
复制标题
基于关系的访问控制策略的安全分析
DOI:
--
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
A. Masoumzadeh
中科院分区:
文献类型:
--
作者:
A. Masoumzadeh
Relationship-based access control (ReBAC) policies can express intricate protection requirements in terms of relationships among users and resources (which can be modeled as a graph). Such policies are useful in domains beyond online social networks. However, given the updating graph of user and resources in a system and expressive conditions in access control policy rules, it can be very challenging for security administrators to envision what can (or cannot) happen as the protection system evolves. In this paper, we introduce the security analysis problem for this class of policies, where we seek to answer security queries about future states of the system graph and authorizations that are decided accordingly. Towards achieving this goal, we propose a state-transition model of a ReBAC protection system, called RePM. We discuss about formulation of security analysis queries in RePM and present our initial results for a limited version of this model.