A Datalog Framework for Modeling Relationship-based Access Control Policies

被引:21
|
作者
Pasarella, Edelmira [1 ]
Lobo, Jorge [2 ]
机构
[1] Univ Politecn Cataluna, Comp Sci Dept, Barcelona, Spain
[2] Univ Pompeu Fabra, Inst Catalana Recerca & Estudis Avancats ICREA, Barcelona, Spain
关键词
Relationship-based Access Control; security and privacy policies; Datalog; EXPRESSIVE POWER; COMPLEXITY;
D O I
10.1145/3078861.3078871
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Relationships like friendship to limit access to resources have been part of social network applications since their beginnings. Describing access control policies in terms of relationships is not particular to social networks and it arises naturally in many situations. Hence, we have recently seen several proposals formalizing different Relationship-based Access Control (ReBAC) models. In this paper, we introduce a class of Datalog programs suitable for modeling ReBAC and argue that this class of programs, that we called ReBAC Datalog policies, provides a very general framework to specify and implement ReBAC policies. To support our claim, we first formalize the merging of two recent proposals for modeling ReBAC, one based on hybrid logic and the other one based on path regular expressions. We present extensions to handle negative authorizations and temporal policies. We describe mechanism for policy analysis, and then discuss the feasibility of using Datalog-based systems as implementations.
引用
收藏
页码:91 / 102
页数:12
相关论文
共 50 条
  • [41] Framework for supporting distributed access control policies
    Zhou, W
    Meinel, C
    Raja, VH
    10TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS, PROCEEDINGS, 2005, : 442 - 447
  • [42] A MAS security framework implementing reputation based policies and owners access control
    Vitabile, S.
    Milici, G.
    Scolaro, S.
    Sorbello, F.
    Pilato, G.
    20TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 2, PROCEEDINGS, 2006, : 746 - +
  • [43] A Formal Framework for Reflective Database Access Control Policies
    Olson, Lars E.
    Gunter, Carl A.
    Madhusudan, P.
    CCS'08: PROCEEDINGS OF THE 15TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2008, : 289 - 298
  • [44] A Framework for the Analysis of Access Control Policies with Emergency Management
    Alves, Sandra
    Fernandez, Maribel
    ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2015, 312 : 89 - 105
  • [45] A Research Challenge in Modeling Access Control Policies: Modeling Recommendations
    El Kalam, Anas Abou
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON RESEARCH CHALLENGES IN INFORMATION SCIENCE: RCIS 2008, 2007, : 263 - 270
  • [46] A relational database integrity framework for access control policies
    Romuald Thion
    Stéphane Coulondre
    Journal of Intelligent Information Systems, 2012, 38 : 131 - 159
  • [47] A logical framework for reasoning on data access control policies
    Bertino, E
    Buccafurri, F
    Ferrari, E
    Rullo, P
    PROCEEDINGS OF THE 12TH IEEE COMPUTER SECURITY FOUNDATIONS WORKSHOP, 1999, : 175 - 189
  • [48] Logical framework for reasoning on data access control policies
    Bertino, Elisa
    Ferrari, Elena
    Buccafurri, Francesco
    Rullo, Pasquale
    Proceedings of the Computer Security Foundations Workshop, 1999, : 175 - 189
  • [49] A relational database integrity framework for access control policies
    Thion, Romuald
    Coulondre, Stephane
    JOURNAL OF INTELLIGENT INFORMATION SYSTEMS, 2012, 38 (01) : 131 - 159
  • [50] On flexible Modeling of history-based access control policies for XML documents
    Roeder, Patrick
    Tafreschi, Omid
    Eckert, Claudia
    KNOWLEDGE-BASED INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS: KES 2007 - WIRN 2007, PT III, PROCEEDINGS, 2007, 4694 : 1090 - +