Security Analysis of Relationship-Based Access Control Policies

Security Analysis of Relationship-Based Access Control Policies
复制标题

基于关系的访问控制策略的安全分析

DOI:
--
复制
发表时间:
2018
期刊:
Conference on Data and Application Security and Privacy
影响因子:
--
通讯作者:
A. Masoumzadeh
A. Masoumzadeh
中科院分区:
--
文献类型:
--
作者:
A. Masoumzadeh

文献摘要

被引文献

相似文献

基于关系的访问控制(ReBAC)策略可以根据用户和资源之间的关系(可以建模为图)表达复杂的保护需求。这些政策在在线社交网络之外的领域也很有用。然而,考虑到系统中用户和资源的更新图以及访问控制策略规则中的表达条件,安全管理员很难想象随着保护系统的发展会发生什么(或不可能发生什么)。在本文中,我们介绍了这类策略的安全分析问题,其中我们试图回答有关系统图的未来状态和相应决定的授权的安全查询。为了实现这一目标,我们提出了一个ReBAC保护系统的状态转换模型,称为RePM。我们讨论了RePM中安全分析查询的公式,并给出了该模型的有限版本的初步结果。
Relationship-based access control (ReBAC) policies can express intricate protection requirements in terms of relationships among users and resources (which can be modeled as a graph). Such policies are useful in domains beyond online social networks. However, given the updating graph of user and resources in a system and expressive conditions in access control policy rules, it can be very challenging for security administrators to envision what can (or cannot) happen as the protection system evolves. In this paper, we introduce the security analysis problem for this class of policies, where we seek to answer security queries about future states of the system graph and authorizations that are decided accordingly. Towards achieving this goal, we propose a state-transition model of a ReBAC protection system, called RePM. We discuss about formulation of security analysis queries in RePM and present our initial results for a limited version of this model.