A logical framework for reasoning on data access control policies

被引:25
|
作者
Bertino, E [1 ]
Buccafurri, F [1 ]
Ferrari, E [1 ]
Rullo, P [1 ]
机构
[1] Univ Milan, Dipartimento Sci Informaz, I-20135 Milan, Italy
关键词
D O I
10.1109/CSFW.1999.779772
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper we propose a logic formalism that naturally supports rite encoding of complex security specifications. This formalism relies on a hierarchically structured domain made of subjects, objects and privileges. Authorizations are expressed by logic rules. The formalism supports both negation by failure (possibly unstratified) and mle negation. The latter is used to express negative authorizations. It turns out that conflicts may result from a set of authorization rules. Dealing with such conflicts requires the knowledge of the domain structure, such as grantor priorities and object/subject hierarchies, which is used in the deductive process to determine which authorization prevails, if any, on the others. Often, however; conflicts are unsolvable, as they express intrinsic ambiguities. We have devised two semantics as an extension of the well-founded and the stable model semantics of logic programming. We have also defined a number of access policies, each based on two orthogonal choices: one is related to the way how we cope with multiplicity of authorization sets in case of stable model semantics; the other is concerned with the open/closed assumption. A comparative analysis of the proposed authorization policies, based oil their degree of permissivity, shows that they form a complete lattice.
引用
收藏
页码:175 / 189
页数:15
相关论文
共 50 条
  • [41] PolicyMorph: Interactive Policy Transformations for a Logical Attribute-Based Access Control Framework
    LeMay, Michael
    Fatemieh, Omid
    Gunter, Carl A.
    SACMAT'07: PROCEEDINGS OF THE 12TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2007, : 205 - 214
  • [42] Dynamic access-control policies on XML encrypted data
    Bouganim, Luc
    Ngoc, Francois Dang
    Pucheral, Philippe
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2008, 10 (04)
  • [43] Enabling role-based web access control using a declarative logical framework
    Chamizo, Javier
    Mencke, Myriam
    Gomez, Juan Miguel
    Alor-Hernandez, Giner
    2008 IEEE 24TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING WORKSHOP, VOLS 1 AND 2, 2008, : 390 - +
  • [44] A Four-Valued Logical Framework for Reasoning About Fiction
    Peron, Newton
    Antunes, Henrique
    LOGIC AND LOGICAL PHILOSOPHY, 2022, 31 (04) : 579 - 610
  • [45] Preferred subtheories. An extended logical framework for default reasoning
    1600, Morgan Kaufmann Publ Inc, San Mateo, CA, USA (02):
  • [46] AN ALTERNATIVE LOGICAL FRAMEWORK FOR DIALECTICAL REASONING IN THE SOCIAL AND POLICY SCIENCES
    SABRE, RM
    THEORY AND DECISION, 1991, 30 (03) : 187 - 211
  • [47] A LOGICAL VIEW OF NONMONOTONICITY IN ACCESS CONTROL
    Ravari, Ali Noorollahi
    Fallah, Mehran S.
    SECRYPT 2011: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2011, : 472 - 481
  • [48] A Framework to Enforce Access Control over Data Streams
    Carminati, Barbara
    Dicom, Elena Ferrari
    Cao, Jianneng
    Tan, Kian Lee
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2010, 13 (03)
  • [49] PROBLEMS OF INTERPRETING REASONING DATA - LOGICAL AND PSYCHOLOGICAL APPROACHES
    EVANS, JSBT
    COGNITION, 1972, 1 (04) : 373 - 384
  • [50] Logical Reasoning
    不详
    JOURNAL OF CONSULTING PSYCHOLOGY, 1955, 19 (05): : 405 - 405