A formal graph based framework for supporting authorization delegations and conflict resolutions

被引:3
|
作者
Chun Ruan
Vijay Varadharajan
机构
[1] University of Western Sydney,School of Computing and Information Technology
[2] Macquarie University,Department of Computing
关键词
Access control; Authorization; Conflict resolution;
D O I
10.1007/s10207-003-0018-4
中图分类号
学科分类号
摘要
Authorization delegations and negations are two important features of a flexible access control model. When a system allows both authorization delegation and negation, conflict problems can become crucial since multiple administrators greatly increase the chance of conflicts. However the problem of handling conflicts in authorization delegations has not been explored by researchers. The existing conflict resolution methods seem limited for certain applications and cyclic authorizations can even lead to undesirable situations. This paper presents an authorization framework that can support authorization delegation for both positive and negative authorizations. A conflict resolution method based on the underlying grant-connectivity relation is proposed, which gives higher priorities to the predecessors to achieve controlled delegation. For conflicts where grantors are not grant-connected, our model supports multiple resolution policies so that users can select the specific one that best suits their requirements. In addition, cyclic authorizations are avoided and cascade overriding is supported when an administrative privilege is overridden. We give a formal description of our model and describe in detail the algorithms to implement the model. Our model is represented using labeled digraphs that provide a formal basis for proving the semantic correctness of our model.
引用
收藏
页码:211 / 222
页数:11
相关论文
共 50 条
  • [31] SGP: A Parallel Computing Framework for Supporting Distributed Structural Graph Clustering
    Xia, Xiufeng
    Fang, Peng
    An, Yunzhe
    Zhu, Rui
    Zong, Chuanyu
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2021, PT III, 2022, 13157 : 722 - 736
  • [32] CATT: A Cloud Based Authorization Framework with Trust and Temporal Aspects
    Zahoor, Ehtesham
    Perrin, Olivier
    Bouchami, Ahmed
    2014 INTERNATIONAL CONFERENCE ON COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING (COLLABORATECOM), 2014, : 285 - 294
  • [33] An Autonomic and Policy-based Authorization Framework for OpenFlow Networks
    Rosendo, Daniel
    Endo, Patricia Takako
    Sadok, Djamel
    Kelner, Judith
    2017 13TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2017,
  • [34] Blockchain Based Authentication and Authorization Framework for Remote Collaboration Systems
    Widick, Logan
    Ranasinghe, Ishan
    Dantu, Ram
    Jonnada, Srikanth
    2019 IEEE 20TH INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (WOWMOM), 2019,
  • [35] A Security Framework for IoT Authentication and Authorization based on Blockchain Technology
    Pajooh, Houshyar Honar
    Rashid, M. A.
    2019 18TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS/13TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (TRUSTCOM/BIGDATASE 2019), 2019, : 264 - 271
  • [36] Supporting attribute-based access control in authorization and authentication infrastructures with ontologies
    Priebe, Torsten
    Dobmeier, Wolfgang
    Schläger, Christian
    Kamprath, Nora
    Journal of Software, 2007, 2 (01) : 27 - 38
  • [37] Efficient Equality Test on Identity-Based Ciphertexts Supporting Flexible Authorization
    Li, Na
    ENTROPY, 2023, 25 (02)
  • [38] Multilevel Conflict Analysis Based on Fuzzy Formal Contexts
    Zhi, Huilai
    Li, Jinhai
    Li, Yinan
    IEEE TRANSACTIONS ON FUZZY SYSTEMS, 2022, 30 (12) : 5128 - 5142
  • [39] The transmission capacity of MANET based on conflict graph
    Yu, Gen-jian
    Zheng, Bao-yu
    2006 IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-4, 2006, : 816 - 819
  • [40] THE TRANSMISSION CAPACITY OF MANET BASED ON CONFLICT GRAPH
    Yu Genjian Zheng Baoyu (Department of Information Engineering
    Journal of Electronics(China), 2007, (06) : 798 - 805