Comparing rule-based policies

被引:1
|
作者
Bonatti, P. A. [1 ]
Mogavero, F. [1 ]
机构
[1] Univ Naples Federico II, I-80126 Naples, Italy
关键词
D O I
10.1109/POLICY.2008.16
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Policy comparison is useful for a variety of applications, including policy validation and policy-aware service selection. While policy comparison is somewhat natural for policy languages based on description logics, it becomes rather difficult for rule-based policies. When policies have recursive rules, the problem is in general undecidable. Still most policies require some form of recursion to model-say-subject and object hierarchies, and certificate chains. In this paper we show how policies with recursion can be compared by adapting query optimization techniques developed for the relational algebra. We prove soundness and completeness of our method, discuss the compatibility of the restrictive assumptions we need w.r.t. our reference application scenarios, and report the results of a preliminary set of experiments to prove the practical applicability of our approach.
引用
收藏
页码:11 / 18
页数:8
相关论文
共 50 条
  • [21] Converting Rule-Based Access Control Policies: From Complemented Conditions to Deny Rules
    Ruiz, Josue A.
    Narendran, Paliath
    Masoumzadeh, Amir
    Iyer, Padmavathi
    PROCEEDINGS OF THE 29TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, SACMAT 2024, 2024, : 159 - 169
  • [22] A representation of network node QoS control policies using rule-based building blocks
    Kanada, Y
    IEEE 2000 EIGHTH INTERNATIONAL WORKSHOP ON QUALITY OF SERVICE, 2000, : 161 - 163
  • [23] A rule-based lens model
    Yin, Jing
    Rothrock, Ling
    INTERNATIONAL JOURNAL OF INDUSTRIAL ERGONOMICS, 2006, 36 (05) : 499 - 509
  • [24] Validating Rule-based Algorithms
    Laszlo Lengyel
    ACTA POLYTECHNICA HUNGARICA, 2015, 12 (04) : 59 - 75
  • [25] Rule-based ship design
    不详
    NAVAL ARCHITECT, 2007, : 159 - +
  • [26] Evolution of rule-based programs
    Lämmel, R
    JOURNAL OF LOGIC AND ALGEBRAIC PROGRAMMING, 2004, 60-1 : 141 - 193
  • [27] Rule-based runtime verification
    Barringer, H
    Goldberg, A
    Havelund, K
    Sen, K
    VERIFICATION, MODEL CHECKING, AND ABSTRACT INTERPRETATION, PROCEEDINGS, 2004, 2937 : 44 - 57
  • [28] QUALITATIVE, RULE-BASED MODELING
    STARFIELD, AM
    BIOSCIENCE, 1990, 40 (08) : 601 - 604
  • [29] RULE-BASED SIMULATION METAMODELS
    PIERREVAL, H
    EUROPEAN JOURNAL OF OPERATIONAL RESEARCH, 1992, 61 (1-2) : 6 - 17
  • [30] Rule-Based Programming with Diaplan
    Drewes, Frank
    Hoffmann, Berthold
    Klein, Raimund
    Minas, Mark
    ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2005, 127 (01) : 15 - 26