A Datalog Framework for Modeling Relationship-based Access Control Policies

被引:21
|
作者
Pasarella, Edelmira [1 ]
Lobo, Jorge [2 ]
机构
[1] Univ Politecn Cataluna, Comp Sci Dept, Barcelona, Spain
[2] Univ Pompeu Fabra, Inst Catalana Recerca & Estudis Avancats ICREA, Barcelona, Spain
关键词
Relationship-based Access Control; security and privacy policies; Datalog; EXPRESSIVE POWER; COMPLEXITY;
D O I
10.1145/3078861.3078871
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Relationships like friendship to limit access to resources have been part of social network applications since their beginnings. Describing access control policies in terms of relationships is not particular to social networks and it arises naturally in many situations. Hence, we have recently seen several proposals formalizing different Relationship-based Access Control (ReBAC) models. In this paper, we introduce a class of Datalog programs suitable for modeling ReBAC and argue that this class of programs, that we called ReBAC Datalog policies, provides a very general framework to specify and implement ReBAC policies. To support our claim, we first formalize the merging of two recent proposals for modeling ReBAC, one based on hybrid logic and the other one based on path regular expressions. We present extensions to handle negative authorizations and temporal policies. We describe mechanism for policy analysis, and then discuss the feasibility of using Datalog-based systems as implementations.
引用
收藏
页码:91 / 102
页数:12
相关论文
共 50 条
  • [21] Relationship-Based Threat Modeling
    Verreydt, Stef
    Sion, Laurens
    Yskout, Koen
    Joosen, Wouter
    3RD INTERNATIONAL WORKSHOP ON ENGINEERING AND CYBERSECURITY OF CRITICAL SYSTEMS (ENCYCRIS 2022), 2022, : 41 - 48
  • [22] Attributes Aware Relationship-based Access Control for Smart IoT Systems
    Praharaj, Lopamudra
    Ameer, Safwa
    Gupta, Maanak
    Sandhu, Ravi
    2022 IEEE 8TH INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING, CIC, 2022, : 72 - 81
  • [23] Relationship-based federated access control model for EPC Discovery Service
    Liu, Bing
    Chu, Chao-Hsien
    COMPUTERS & SECURITY, 2015, 55 : 251 - 270
  • [24] Relationship-Based Access Control for Resharing in Decentralized Online Social Networks
    Gay, Richard
    Hu, Jinwei
    Mantel, Heiko
    Mazaheri, Sogol
    FOUNDATIONS AND PRACTICE OF SECURITY (FPS 2017), 2018, 10723 : 18 - 34
  • [25] Attribute-Aware Relationship-Based Access Control for Online Social Networks
    Cheng, Yuan
    Park, Jaehong
    Sandhu, Ravi
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXVIII, 2014, 8566 : 292 - 306
  • [26] On Feasibility of Attribute-Aware Relationship-Based Access Control Policy Mining
    Chakraborty, Shuvra
    Sandhu, Ravi
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXV, 2021, 12840 : 393 - 405
  • [27] A relationship-based framework of spirituality for individuals with HIV
    Tarakeshwar, N
    Khan, N
    Sikkema, KJ
    AIDS AND BEHAVIOR, 2006, 10 (01) : 59 - 70
  • [28] A Relationship-Based Framework of Spirituality for Individuals with HIV
    Nalini Tarakeshwar
    Nadia Khan
    Kathleen J. Sikkema
    AIDS and Behavior, 2006, 10 : 59 - 70
  • [29] Modeling of Online Social Network Policies Using an Attribute-Based Access Control Framework
    Bennett, Phillipa
    Ray, Indrakshi
    France, Robert
    INFORMATION SYSTEMS SECURITY, (ICISS 2015), 2015, 9478 : 79 - 97
  • [30] A User-to-User Relationship-Based Access Control Model for Online Social Networks
    Cheng, Yuan
    Park, Jaehong
    Sandhu, Ravi
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXVI, 2012, 7371 : 8 - 24