A logical framework for reasoning about access control models

被引:89
|
作者
Bertino, Elisa [1 ,4 ]
Catania, Barbara [2 ,5 ]
Ferrari, Elena [3 ,6 ]
Perlasca, Paolo [1 ,4 ]
机构
[1] DSI, Università di Milano
[2] DISI, Università di Geneva
[3] DSCFM, Università dell'Insubria
[4] Dipto. di Scienze dell'Informazione, Univ. degli Studi di Milano, via Comelico 39/41, 20135 Milano, Italy
[5] Dipartimento di Informatica, Università di Geneva, via Dodeoaneso 35, 16146 Genova, Italy
[6] Dipto. di Scienze Chimiche, Università dell'Insubria, via Valleggio 11, 22100 Como, Italy
关键词
Access control models - Database administration - Model specification;
D O I
10.1145/605434.605437
中图分类号
学科分类号
摘要
The increased awareness of the importance of data protection has made access control a relevant component of current data management systems. Moreover, emerging applications and data models call for flexible and expressive access control models. This has led to an extensive research activity that has resulted in the definition of a variety of access control models that differ greatly with respect to the access control policies they support. Thus, the need arises for developing tools for reasoning about the characteristics of these models. These tools should support users in the tasks of model specification, analysis of model properties, and authorization management. For example, they must be able to identify inconsistencies in the model specification and must support the administrator in comparing the expressive power of different models. In this paper, we make a first step in this direction by proposing a formal framework for reasoning about access control models. The framework we propose is based on a logical formalism and is general enough to model discretionary, mandatory, and role-based access control models. Each instance of the proposed framework corresponds to a C-Datalog program, interpreted according to a stable model semantics. In the paper, besides giving the syntax and the formal semantics of our framework, we show some examples of its application. Additionally, we present a number of dimensions along which access control models can be analyzed and compared. For each dimension, we show decidability results and we present some examples of its application.
引用
收藏
页码:71 / 127
相关论文
共 50 条
  • [1] Logical Method for Reasoning About Access Control and Data Flow Control Models
    Logrippo, Luigi
    FOUNDATIONS AND PRACTICE OF SECURITY (FPS 2014), 2015, 8930 : 205 - 220
  • [2] Logical framework for reasoning on data access control policies
    Bertino, Elisa
    Ferrari, Elena
    Buccafurri, Francesco
    Rullo, Pasquale
    Proceedings of the Computer Security Foundations Workshop, 1999, : 175 - 189
  • [3] A logical framework for reasoning on data access control policies
    Bertino, E
    Buccafurri, F
    Ferrari, E
    Rullo, P
    PROCEEDINGS OF THE 12TH IEEE COMPUTER SECURITY FOUNDATIONS WORKSHOP, 1999, : 175 - 189
  • [4] Reasoning about trust: A formal logical framework
    Demolombe, R
    TRUST MANAGEMENT, PROCEEDING, 2004, 2995 : 291 - 303
  • [5] A logical framework for modeling and reasoning about the evolution of requirements
    Zowghi, D
    Offen, R
    RE '97 - PROCEEDINGS OF THE THIRD IEEE INTERNATIONAL SYMPOSIUM ON REQUIREMENTS ENGINEERING, 1997, : 247 - 257
  • [6] A Four-Valued Logical Framework for Reasoning About Fiction
    Peron, Newton
    Antunes, Henrique
    LOGIC AND LOGICAL PHILOSOPHY, 2022, 31 (04) : 579 - 610
  • [7] A Unified Logical Framework for Reasoning about Deontic Properties of Actions and States
    Kulicki, Piotr
    Trypuz, Robert
    Craven, Robert
    Sergot, Marek
    LOGIC AND LOGICAL PHILOSOPHY, 2023, 32 (04) : 583 - 617
  • [8] A Logical Framework for Reasoning About Local and Global Properties of Collective Systems
    Michele, Loreti
    Rehman, Aniqa
    QUANTITATIVE EVALUATION OF SYSTEMS (QEST 2022), 2022, 13479 : 133 - 149
  • [9] A LOGICAL FRAMEWORK FOR DEFAULT REASONING
    POOLE, D
    ARTIFICIAL INTELLIGENCE, 1988, 36 (01) : 27 - 47
  • [10] An Ontological Framework for Reasoning about Relations between Complex Access Control Policies in Cloud Environments
    Veloudis, Simeon
    Paraskakis, Iraklis
    Petsos, Christos
    CLOSER: PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE, 2019, : 355 - 362