A formal graph based framework for supporting authorization delegations and conflict resolutions

被引:3
|
作者
Chun Ruan
Vijay Varadharajan
机构
[1] University of Western Sydney,School of Computing and Information Technology
[2] Macquarie University,Department of Computing
关键词
Access control; Authorization; Conflict resolution;
D O I
10.1007/s10207-003-0018-4
中图分类号
学科分类号
摘要
Authorization delegations and negations are two important features of a flexible access control model. When a system allows both authorization delegation and negation, conflict problems can become crucial since multiple administrators greatly increase the chance of conflicts. However the problem of handling conflicts in authorization delegations has not been explored by researchers. The existing conflict resolution methods seem limited for certain applications and cyclic authorizations can even lead to undesirable situations. This paper presents an authorization framework that can support authorization delegation for both positive and negative authorizations. A conflict resolution method based on the underlying grant-connectivity relation is proposed, which gives higher priorities to the predecessors to achieve controlled delegation. For conflicts where grantors are not grant-connected, our model supports multiple resolution policies so that users can select the specific one that best suits their requirements. In addition, cyclic authorizations are avoided and cascade overriding is supported when an administrative privilege is overridden. We give a formal description of our model and describe in detail the algorithms to implement the model. Our model is represented using labeled digraphs that provide a formal basis for proving the semantic correctness of our model.
引用
收藏
页码:211 / 222
页数:11
相关论文
共 50 条
  • [21] A Formal Framework and a Tool for the Specification and Analysis of G-Nets Models Based on Graph Transformation
    Kerkouche, Elhillali
    Chaoui, Allaoua
    DISTRIBUTED COMPUTING AND NETWORKING, 2009, 5408 : 206 - +
  • [22] Sociopsychological analysis of conflict-supporting narratives: A general framework
    Bar-Tal, Daniel
    Oren, Neta
    Nets-Zehngut, Rafi
    JOURNAL OF PEACE RESEARCH, 2014, 51 (05) : 662 - 675
  • [23] Weighted directed graph-based authorization delegation model
    Lei, Jianyun
    Journal of Networks, 2013, 8 (12) : 2812 - 2815
  • [24] Open Social and XACML based Group Authorization Framework
    Zhang, Hui
    Li, ZhenAn
    Wu, Wenjun
    SECOND INTERNATIONAL CONFERENCE ON CLOUD AND GREEN COMPUTING / SECOND INTERNATIONAL CONFERENCE ON SOCIAL COMPUTING AND ITS APPLICATIONS (CGC/SCA 2012), 2012, : 655 - 659
  • [25] An XML standards based authorization framework for mobile agents
    Navarro, G.
    Borrell, J.
    SECURE MOBILE AD-HOC NETWORKS AND SENSORS, 2006, 4074 : 54 - 66
  • [26] Conflict Graph based Community Detection
    Singh, Priti
    Chakraborty, Abhishek
    Manoj, B. S.
    2016 8TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORKS (COMSNETS), 2016,
  • [27] Graph transformation as a conceptual and formal framework for system modeling and model evolution
    Engels, G
    Heckel, R
    AUTOMATA LANGUAGES AND PROGRAMMING, 2000, 1853 : 127 - 150
  • [28] SUPPORTING FORMAL VERIFICATION OF DIMA MULTI-AGENTS MODELS: TOWARDS FRAMEWORK BASED ON MAUDE MODEL CHECKING
    Boudiaf, Noura
    Mokhati, Farid
    Badri, Mourad
    INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2008, 18 (07) : 853 - 875
  • [29] Research on Authorization Model of Attribute Access Control Based on Knowledge Graph
    Ma, Li
    Lao, Qidi
    Yang, Wenyin
    Yang, Zexian
    Yuan, Dong
    Bu, Zhaoxiong
    UBIQUITOUS SECURITY, UBISEC 2023, 2024, 2034 : 348 - 359
  • [30] Graph matching based authorization model for efficient secure XML querying
    Chang, Seunghan
    Chebotko, Artem
    Lu, Shiyong
    Fotouhi, Farshad
    21ST INTERNATIONAL CONFERENCE ON ADVANCED NETWORKING AND APPLICATIONS WORKSHOPS/SYMPOSIA, VOL 2, PROCEEDINGS, 2007, : 473 - +