Specifying distributed authorization with delegation using logic programming

被引:0
|
作者
Wang, S [1 ]
Zhang, Y [1 ]
机构
[1] Univ Western Sydney, Sydney, NSW, Australia
关键词
ACCESS-CONTROL POLICIES;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Trust management is a promising approach for the authorization in distributed environment. There are two key issues for a trust management system: how to design high-level policy language and how to solve the compliance-checking problem [3, 4]. We adopt this approach to deal with distributed authorization with delegation. In this paper, we propose an authorization language AL, a human-understandable high level language to specify various authorization policies. Language AL has rich expressive power which can not only specify delegation, and threshold structures addressed in previous approaches, but also represent structured resources and privileges, positive and negative authorizations, separation of duty, incomplete information reasoning and partial authorization and delegation. We define the semantics of AL through logic programming with answer set semantics and through an authorization scenario we demonstrate the application of language AL.
引用
收藏
页码:761 / 767
页数:7
相关论文
共 50 条
  • [1] Handling distributed authorization with delegation through answer set programming
    Wang, Shujing
    Zhang, Yan
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2007, 6 (01) : 27 - 46
  • [2] Handling distributed authorization with delegation through answer set programming
    Shujing Wang
    Yan Zhang
    International Journal of Information Security, 2007, 6 : 27 - 46
  • [3] A logic programming view of authorization in distributed systems
    Winsborough, WH
    LOGIC PROGRAMMING, PROCEEDINGS, 2003, 2916 : 20 - 46
  • [4] A formalization of distributed authorization with delegation
    Wang, SJ
    Zhang, Y
    INFORMATION SECURITY AND PRIVACY, PROCEEDINGS, 2005, 3574 : 303 - 315
  • [5] Distributed Programming with Distributed Authorization
    Avijit, Kumar
    Datta, Anupam
    Harper, Robert
    TLDI '10: PROCEEDINGS OF THE 2010 ACM SIGPLAN WORKSHOP ON TYPES IN LANGUAGE DESIGN AND IMPLEMENTATION, 2010, : 27 - 38
  • [6] A logic model for temporal authorization delegation with negation
    Ruan, C
    Varadharajan, V
    Zhang, Y
    INFORMATION SECURITY, PROCEEDINGS, 2003, 2851 : 310 - 324
  • [7] A Delegation Logic Based Authorization Mechanism for Virtual Organizations
    Gu, Chunhua
    Zhang, Xueqin
    Song, Guoxin
    APPLIED PUBLIC KEY INFRASTRUCTURE, 2005, 128 : 123 - 136
  • [8] Distributed logic programming using mobile agents
    Wang, TI
    Clark, KL
    18TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 2 (REGULAR PAPERS), PROCEEDINGS, 2004, : 137 - 142
  • [9] Logic-based knowledge representation for authorization with delegation (extended abstract)
    Li, Ninghui
    Feigenbaum, Joan
    Grosof, Benjamin N.
    Proceedings of the Computer Security Foundations Workshop, 1999, : 162 - 174
  • [10] A logic-based knowledge representation for authorization with delegation (extended abstract)
    Li, N
    Feigenbaum, J
    Grosof, BN
    PROCEEDINGS OF THE 12TH IEEE COMPUTER SECURITY FOUNDATIONS WORKSHOP, 1999, : 162 - 174