A formal graph based framework for supporting authorization delegations and conflict resolutions

被引:3
|
作者
Chun Ruan
Vijay Varadharajan
机构
[1] University of Western Sydney,School of Computing and Information Technology
[2] Macquarie University,Department of Computing
关键词
Access control; Authorization; Conflict resolution;
D O I
10.1007/s10207-003-0018-4
中图分类号
学科分类号
摘要
Authorization delegations and negations are two important features of a flexible access control model. When a system allows both authorization delegation and negation, conflict problems can become crucial since multiple administrators greatly increase the chance of conflicts. However the problem of handling conflicts in authorization delegations has not been explored by researchers. The existing conflict resolution methods seem limited for certain applications and cyclic authorizations can even lead to undesirable situations. This paper presents an authorization framework that can support authorization delegation for both positive and negative authorizations. A conflict resolution method based on the underlying grant-connectivity relation is proposed, which gives higher priorities to the predecessors to achieve controlled delegation. For conflicts where grantors are not grant-connected, our model supports multiple resolution policies so that users can select the specific one that best suits their requirements. In addition, cyclic authorizations are avoided and cascade overriding is supported when an administrative privilege is overridden. We give a formal description of our model and describe in detail the algorithms to implement the model. Our model is represented using labeled digraphs that provide a formal basis for proving the semantic correctness of our model.
引用
收藏
页码:211 / 222
页数:11
相关论文
共 50 条
  • [1] Implementing authorization delegations using graph
    Ruan, Chun
    Varadharajan, Vijay
    DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2006, 4080 : 904 - 913
  • [2] A Formal Authorization Framework for Networked SCADA Systems
    Rysavy, Ondrej
    Rab, Jaroslav
    Halfar, Patrik
    Sveda, Miroslav
    2012 IEEE 19TH INTERNATIONAL CONFERENCE AND WORKSHOPS ON ENGINEERING OF COMPUTER BASED SYSTEMS (ECBS), 2012, : 298 - 302
  • [3] A weighted graph approach to authorization delegation and conflict resolution
    Ruan, C
    Varadharajan, V
    INFORMATION SECURITY AND PRIVACY, PROCEEDINGS, 2004, 3108 : 402 - 413
  • [4] Integration of graph based authorization policies
    Ruan, Chun
    Varadharajan, Vijay
    FOUNDATIONS OF INTELLIGENT SYSTEMS, PROCEEDINGS, 2006, 4203 : 359 - 368
  • [5] SUPPORTING QUERIES ON SOURCE CODE - A FORMAL FRAMEWORK
    PAUL, S
    PRAKASH, A
    INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 1994, 4 (03) : 325 - 348
  • [6] A graph theoretic approach to authorization delegation and conflict resolution in decentralised systems
    Ruan, Chun
    Varadharajan, Vijay
    DISTRIBUTED AND PARALLEL DATABASES, 2010, 27 (01) : 1 - 29
  • [7] A graph theoretic approach to authorization delegation and conflict resolution in decentralised systems
    Chun Ruan
    Vijay Varadharajan
    Distributed and Parallel Databases, 2010, 27 : 1 - 29
  • [8] Communicative framework of conflict resolutions: trials, arbitrations, conciliations and mediations
    Ridao Rodrigo, Susana
    CIRCULO DE LINGUISTICA APLICADA A LA COMUNICACION, 2014, (57): : 85 - 112
  • [9] Development of a genetic algorithm-based graph model for conflict resolution for optimizing resolutions in environmental conflicts
    Pourvaziri, Mitra
    Mahmoudkelaye, Samira
    Yousefi, Saied
    JOURNAL OF HYDROINFORMATICS, 2023, 25 (03) : 927 - 942
  • [10] Efficient Authorization of Graph Database Queries in an Attribute-Supporting ReBAC Model
    Rizvi, Syed Zain R.
    Fong, Philip W. L.
    PROCEEDINGS OF THE EIGHTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY'18), 2018, : 204 - 211