Logic-based approach for enforcing access control

被引:0
|
作者
Bertino, Elisa [1 ]
Buccafurri, Francesco [1 ]
Ferrari, Elena [1 ]
Rullo, Pasquale [1 ]
机构
[1] Universita degli Studi di Milano, Milano, Italy
关键词
Computational linguistics - Data acquisition - Formal logic - Mathematical models;
D O I
10.3233/JCS-2000-82-303
中图分类号
学科分类号
摘要
This paper describes an advanced authorization mechanism based on a logic formalism. The model supports both positive and negative authorizations. It also supports derivation rules by which an authorization can be granted on the basis of the presence or absence of other authorizations. Subjects, objects and authorization types are organized into hierarchies, supporting a more adequate representation of their semantics. From the authorizations explicitly specified, additional authorizations are automatically derived by the system, based on those hierarchies. The combination of all the above features results in a powerful yet flexible access control mechanism. The logic formalism on which the system relies is an extension of Ordered Logic with ordered domains. This is an elegant yet powerful formalism whereby the basic concepts of the authorization model can be naturally formalized. Its semantics is based on the notion of stable model and assigns, to a given set of authorization rules, a multiplicity of (stable) models, each representing a possible way of assigning access authorizations. This form of non-determinism entails an innovative approach to enforce access control: when an access request is issued, the appropriate model (set of consistent access authorizations) is chosen, on the basis of the accesses currently under execution in the system.
引用
收藏
页码:109 / 139
相关论文
共 50 条
  • [21] A logic-based approach to semantic information extraction
    Ruffolo, Massimo
    Manna, Marco
    ICEIS 2006: PROCEEDINGS OF THE EIGHTH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS: ARTIFICIAL INTELLIGENCE AND DECISION SUPPORT SYSTEMS, 2006, : 115 - 123
  • [22] LOGIC-BASED APPROACH TO EXPERT SYSTEMS IN CHEMISTRY
    AKUTSU, T
    SUZUKI, E
    OHSUGA, S
    KNOWLEDGE-BASED SYSTEMS, 1991, 4 (02) : 103 - 116
  • [23] A logic-based approach to program flow analysis
    Mooly Sagiv
    Nissim Francez
    Michael Rodeh
    Reinhard Wilhelm
    Acta Informatica, 1998, 35 : 457 - 504
  • [24] A logic-based approach for matching user profiles
    Calì, A
    Calvanese, D
    Colucci, S
    Di Noia, T
    Donini, FM
    KNOWLEDGE-BASED INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS, PT 3, PROCEEDINGS, 2004, 3215 : 187 - 195
  • [25] A logic-based approach to program flow analysis
    Sagiv, M
    Francez, N
    Rodeh, M
    Wilhelm, R
    ACTA INFORMATICA, 1998, 35 (06) : 457 - 504
  • [26] A logic-based approach to combinatorial testing with constraints
    Calvagna, Andrea
    Gargantini, Angelo
    TESTS AND PROOFS, 2008, 4966 : 66 - +
  • [27] Optimize revamp projects with a logic-based approach
    Golden, S
    Moore, J
    Nigg, J
    HYDROCARBON PROCESSING, 2003, 82 (09): : 75 - 83
  • [28] LOGIC-BASED APPROACH TO SEMANTIC QUERY OPTIMIZATION
    CHAKRAVARTHY, US
    GRANT, J
    MINKER, J
    ACM TRANSACTIONS ON DATABASE SYSTEMS, 1990, 15 (02): : 162 - 207
  • [29] A Logic-Based Incremental Approach to Graph Repair
    Schneider, Sven
    Lambers, Leen
    Orejas, Fernando
    FUNDAMENTAL APPROACHES TO SOFTWARE ENGINEERING (FASE 2019), 2019, 11424 : 151 - 167
  • [30] A logic-based approach to mining inductive databases
    Liu, Hong-Cheu
    Yu, Jeffrey Xu
    Zeleznikow, John
    Guan, Ying
    COMPUTATIONAL SCIENCE - ICCS 2007, PT 1, PROCEEDINGS, 2007, 4487 : 270 - 277