A graph theoretic approach to authorization delegation and conflict resolution in decentralised systems

被引:0
|
作者
Ruan, Chun [1 ]
Varadharajan, Vijay [1 ,2 ]
机构
[1] Univ Western Sydney, Sch Comp & Math, Penrith, NSW 1797, Australia
[2] Macquarie Univ, Dept Comp, N Ryde, NSW 2109, Australia
关键词
Access control; Authorization delegation; Conflict resolution; Weighted graph; ACCESS-CONTROL; SECURITY; MODEL;
D O I
10.1007/s10619-009-7044-9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The problem of resolving conflicts in delegated authorizations has not been systematically addressed by researchers. In (Ruan and Varadharajan in Proceedings of the 7th Australasian Conference on Information Security and Privacy, pp. 271-285, 2002) we proposed a graph based framework that supports authorization delegation and conflict resolution. In this paper, we have extended the model to allow grantors of delegations to express degrees of certainties about their delegations and grants of authorizations. This expression of certainty gives the subjects (e.g. users) more flexibility to control their delegations of access rights. We propose a new conflict resolution policy based on weighted lengths of authorization paths. This policy provides a greater degree of flexibility in that it enables to specify and analyse the effect of predecessor-successor relationship as well as the weights of authorizations on the conflicts. We present a detailed algorithm to evaluate authorization delegations and conflict resolutions. The correctness proof and time complexity of the algorithm are also provided. Since in a dynamic environment, the authorization state is not static, we have considered how authorization state changes occur and have developed an algorithm to analyse authorization state transformations and given correctness proofs. Finally, we discuss how to achieve a global decision policy from local authorization policies in a distributed environment. Three integration models based on the degrees of node autonomy are proposed, and different strategies of integrating the local policies into the global policies in each model are systematically discussed.
引用
收藏
页码:1 / 29
页数:29
相关论文
共 50 条
  • [31] GRAPH-THEORETIC APPROACH TO SYMBOLIC ANALYSIS OF LINEAR DESCRIPTOR SYSTEMS
    REINSCHKE, KJ
    LINEAR ALGEBRA AND ITS APPLICATIONS, 1994, 198 : 217 - 244
  • [32] Graph theoretic approach to characterisation of quotient fixed modes in LTI systems
    Abdolmaleki, Mohammad
    Aldeen, Mohammad
    EUROPEAN JOURNAL OF CONTROL, 2016, 31 : 41 - 51
  • [33] A graph theoretic approach to Modeling subsystem dependencies within complex systems
    Skinner, Stephen C.
    Stracener, Jerrell T.
    WMSCI 2007: 11TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL III, PROCEEDINGS, 2007, : 41 - +
  • [34] FAULT-DIAGNOSIS IN DYNAMIC-SYSTEMS - A GRAPH THEORETIC APPROACH
    RAO, SVN
    VISWANADHAM, N
    INTERNATIONAL JOURNAL OF SYSTEMS SCIENCE, 1987, 18 (04) : 687 - 695
  • [35] Observability analysis for structured bilinear systems: A graph-theoretic approach
    Boukhobza, T.
    Hamelin, F.
    AUTOMATICA, 2007, 43 (11) : 1968 - 1974
  • [36] Unilateral delegation and reimbursement systems in an environmental conflict
    Lim, BI
    Shogren, JF
    APPLIED ECONOMICS LETTERS, 2004, 11 (08) : 489 - 493
  • [37] An Interactive Portfolio Decision Analysis Approach for System-of-Systems Architecting Using the Graph Model for Conflict Resolution
    Ge, Bingfeng
    Hipel, Keith W.
    Fang, Liping
    Yang, Kewei
    Chen, Yingwu
    IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2014, 44 (10): : 1328 - 1346
  • [38] Modeling and analysis of component-based software systems: A graph theoretic systems approach
    Upadhyay N.
    Deshpande B.M.
    Agrawal V.P.
    Systems Research Forum, 2010, 4 (02): : 151 - 172
  • [39] An Approach to Verification of a Family of Multiagent Systems for Conflict Resolution
    Garanina N.O.
    Sidorova E.A.
    Automatic Control and Computer Sciences, 2017, 51 (7) : 498 - 506
  • [40] A graph theoretic approach to automata minimality
    Restivo, Antonio
    Vaglica, Roberto
    THEORETICAL COMPUTER SCIENCE, 2012, 429 : 282 - 291