Automated Analysis of Semantic-Aware Access Control Policies: a Logic-Based Approach

被引:1
|
作者
Armando, Alessandro [1 ,2 ]
Carbone, Roberto [2 ]
Ranise, Silvio [2 ]
机构
[1] Univ Genoa, DIST, AI Lab, Viale Causa 13, I-16145 Genoa, Italy
[2] FBK, Secur & Trust Unit, I-38123 Trento, Italy
关键词
semantic-aware access control; automatic analysis; logic-based methods;
D O I
10.1109/ICSC.2011.74
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As the number and sophistication of on-line applications increase, there is a growing concern on how access to sensitive resources (e.g., personal health records) is regulated. Since ontologies can support the definition of fine-grained policies as well as the combination of heterogeneous policies, semantic technologies are expected to play an important role in this context. But understanding the implications of the access control policies of the needed complexity goes beyond the ability of a security administrator. Automatic support to the analysis of access control policies is therefore needed. In this paper we present an automatic analysis technique for access control policies that reduces the reachability problem for access control policies to satisfiability problems in a decidable fragment of first-order logic for which efficient solvers exist. We illustrate the application of our technique on an access control model inspired by a Personal Health Application of real-world complexity.
引用
收藏
页码:356 / 363
页数:8
相关论文
共 50 条
  • [1] Semantic-Aware Access Control for Grid Application
    Chen, Xiyuan
    Yang OUYang
    Zhu, Miaoliang
    He, Yan
    [J]. PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE FOR YOUNG COMPUTER SCIENTISTS, VOLS 1-5, 2008, : 971 - 975
  • [2] Distributed access control: A logic-based approach
    Barker, S
    [J]. COMPUTER NETWORK SECURITY, 2003, 2776 : 217 - 228
  • [3] A Semantic-Aware Attribute-Based Access Control Model for Web Services
    Shen, Haibo
    [J]. ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, PROCEEDINGS, 2009, 5574 : 693 - 703
  • [4] A Semantic-Aware Role-Based Access Control Model for Pervasive Computing Environments
    Javadi, Seyyed Ahmad
    Amini, Morteza
    [J]. ISECURE-ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2013, 5 (02): : 119 - 140
  • [5] A Semantic-Aware Context-Based Access Control Framework for Mobile Web Services
    Shen, Haibo
    Cheng, Yu
    [J]. MECHANICAL ENGINEERING AND INTELLIGENT SYSTEMS, PTS 1 AND 2, 2012, 195-196 : 498 - 503
  • [6] A logic-based approach to semantic information extraction
    Ruffolo, Massimo
    Manna, Marco
    [J]. ICEIS 2006: PROCEEDINGS OF THE EIGHTH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS: ARTIFICIAL INTELLIGENCE AND DECISION SUPPORT SYSTEMS, 2006, : 115 - 123
  • [7] LOGIC-BASED APPROACH TO SEMANTIC QUERY OPTIMIZATION
    CHAKRAVARTHY, US
    GRANT, J
    MINKER, J
    [J]. ACM TRANSACTIONS ON DATABASE SYSTEMS, 1990, 15 (02): : 162 - 207
  • [9] Managing semantic-aware policies in a distributed firewall scenario
    Martinez Perez, Gregorio
    Garcia Clemente, Felix J.
    Gomez Skarmeta, Antonio F.
    [J]. INTERNET RESEARCH, 2007, 17 (04) : 362 - 377
  • [10] A Semantic Logic-Based Approach to Determine Textual Similarity
    Blanco, Eduardo
    Moldovan, Dan
    [J]. IEEE-ACM TRANSACTIONS ON AUDIO SPEECH AND LANGUAGE PROCESSING, 2015, 23 (04) : 683 - 693