A logical framework for reasoning on data access control policies

被引:25
|
作者
Bertino, E [1 ]
Buccafurri, F [1 ]
Ferrari, E [1 ]
Rullo, P [1 ]
机构
[1] Univ Milan, Dipartimento Sci Informaz, I-20135 Milan, Italy
关键词
D O I
10.1109/CSFW.1999.779772
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper we propose a logic formalism that naturally supports rite encoding of complex security specifications. This formalism relies on a hierarchically structured domain made of subjects, objects and privileges. Authorizations are expressed by logic rules. The formalism supports both negation by failure (possibly unstratified) and mle negation. The latter is used to express negative authorizations. It turns out that conflicts may result from a set of authorization rules. Dealing with such conflicts requires the knowledge of the domain structure, such as grantor priorities and object/subject hierarchies, which is used in the deductive process to determine which authorization prevails, if any, on the others. Often, however; conflicts are unsolvable, as they express intrinsic ambiguities. We have devised two semantics as an extension of the well-founded and the stable model semantics of logic programming. We have also defined a number of access policies, each based on two orthogonal choices: one is related to the way how we cope with multiplicity of authorization sets in case of stable model semantics; the other is concerned with the open/closed assumption. A comparative analysis of the proposed authorization policies, based oil their degree of permissivity, shows that they form a complete lattice.
引用
收藏
页码:175 / 189
页数:15
相关论文
共 50 条
  • [1] Logical framework for reasoning on data access control policies
    Bertino, Elisa
    Ferrari, Elena
    Buccafurri, Francesco
    Rullo, Pasquale
    Proceedings of the Computer Security Foundations Workshop, 1999, : 175 - 189
  • [2] A logical framework for reasoning about access control models
    Bertino, Elisa
    Catania, Barbara
    Ferrari, Elena
    Perlasca, Paolo
    ACM Transactions on Information and System Security, 2003, 6 (01) : 71 - 127
  • [3] Logical Method for Reasoning About Access Control and Data Flow Control Models
    Logrippo, Luigi
    FOUNDATIONS AND PRACTICE OF SECURITY (FPS 2014), 2015, 8930 : 205 - 220
  • [4] A logical framework for data-driven reasoning
    Baldi, Paolo
    Corsi, Esther Anna
    Hosni, Hykel
    LOGIC JOURNAL OF THE IGPL, 2024,
  • [5] An Ontological Framework for Reasoning about Relations between Complex Access Control Policies in Cloud Environments
    Veloudis, Simeon
    Paraskakis, Iraklis
    Petsos, Christos
    CLOSER: PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE, 2019, : 355 - 362
  • [6] A LOGICAL FRAMEWORK FOR DEFAULT REASONING
    POOLE, D
    ARTIFICIAL INTELLIGENCE, 1988, 36 (01) : 27 - 47
  • [7] A framework for automated negotiation of access control policies
    Bharadwaj, VG
    Baras, JS
    DARPA INFORMATION SURVIVABILITY CONFERENCE AND EXPOSITION, VOL II, PROCEEDINGS, 2003, : 216 - 221
  • [8] Framework for supporting distributed access control policies
    Zhou, W
    Meinel, C
    Raja, VH
    10TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS, PROCEEDINGS, 2005, : 442 - 447
  • [9] Specifying and reasoning about dynamic access-control policies
    Dougherty, Daniel J.
    Fisler, Kathi
    Krishnamurthi, Shriram
    AUTOMATED REASONING, PROCEEDINGS, 2006, 4130 : 632 - 646
  • [10] Qualitative spatial reasoning in a logical framework
    Raffaetà, A
    Renso, C
    Turini, R
    AI(ASTERISK)IA 2003: ADVANCES IN ARTIFICIAL INTELLIGENCE, PROCEEDINGS, 2003, 2829 : 78 - 90