课题基金 / 基金详情

Strengthening the Foundations of Access Control

Strengthening the Foundations of Access Control
加强访问控制的基础
批准号:
RGPIN-2014-06716
负责人:
Tripunitara, Mahesh
金额:
$2.84万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2016
资助国家:
加拿大
项目状态:
已结题
起止时间:
2016-01-01 至 2017-12-31

项目摘要

项目成果

Tripunitara, Mahesh的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Access control comprises the techniques and mechanisms by which we ensure that only authorized principals are able to perform certain actions, such as read and write, on resources. It is an essential component of the security of deployed systems, and is also an active area of research. From the PI's experience over the past few years, which includes collaborative research with industry, he has learned that the foundations of access control need considerable work. This is the focus of this proposal. The proposed research fits into the PI's longer term vision of making computer systems, on which all of us increasingly rely for even our basic needs, as secure as is feasible. The PI proposes to address three fundamental topics. One is forensics, with which we answer questions about past states of a system. Forensics is important because preventive security techniques often fail. Access control systems are an important context in which to perform forensic analysis; however, the forensic analysis problem has not been posed as such in prior research. The PI proposes to precisely pose and investigate a broad class of forensic analysis problems in the context of access control. One of the outcomes of this work will be goal-directed logging, so only essential logs are maintained that lend to efficient analysis. A second topic that the PI proposes to research is the secrecy resilience of authorization policies. Authorization policies are themselves resources that need to be protected because portions of them (e.g., whether a user has a certain privilege) may be sensitive to disclosure. The central question that the PI proposes to answer in this context is: are some authorization policies inherently more secrecy resilient than others? The PI proposes to evolve a notion of secrecy resilience that has intuitive appeal, and explore several research directions, such as whether it is possible to increase the secrecy resilience of a policy without changing its effective authorizations, and whether one can build Role-Based Access Control (RBAC) policies that have a desired secrecy resilience. The third topic that the PI proposes to research is the foundations of testing implementations of authorization and access control systems. This is a topic on which the PI has conducted some recent work in collaboration with industry partners. There are several research problems that the PI proposes to address in this context. One is the identification and development of an appropriate syntax and associated semantics to express authorization systems for the purpose of testing, and the properties for which we would like to test. Another is a theory that relates such declarative properties with procedural traces, instances of which are to be exercised on the system under test. The PI proposes also to develop techniques for automatically generating trace instances using existing tools such as model checkers, and tying that to the process of exercising the trace instances. All of this work will result in a complete testing ecosystem for real world authorization and access control systems. The proposed research is of value to Canada, and will complement the PI's other research, including those he performs in collaboration with industry partners. It will be high-impact in three ways. It will train Highly Qualified Personnel (HQP) in the important area of computer security, it will result in high-quality research publications in prestigious and selective journals and conferences, which in turn will give graduate students valuable exposure to the larger research community, and it will provide the PI and other researchers greater avenues to form research collaborations with Canadian industry partners by way of applying the proposed work to their real world problems.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Trust, in an Internet of Things
  • 批准号:
    RGPIN-2019-05634
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.04万
  • 财政年份:
    2022
  • 负责人:
    Tripunitara, Mahesh
  • 依托单位:
Trust, in an Internet of Things
  • 批准号:
    RGPIN-2019-05634
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.04万
  • 财政年份:
    2021
  • 负责人:
    Tripunitara, Mahesh
  • 依托单位:
Software Dependability for 5G Systems
  • 批准号:
    532264-2018
  • 项目类别:
    Collaborative Research and Development Grants
  • 资助金额:
    $9.98万
  • 财政年份:
    2021
  • 负责人:
    Tripunitara, Mahesh
  • 依托单位:
Software Dependability for 5G Systems
  • 批准号:
    532264-2018
  • 项目类别:
    Collaborative Research and Development Grants
  • 资助金额:
    $10.2万
  • 财政年份:
    2020
  • 负责人:
    Tripunitara, Mahesh
  • 依托单位:
海外基金