Towards A Generic Formal Framework for Access Control Systems
نویسندگان
چکیده
There have been many proposals for access control models and authorization policy languages, which are used to inform the design of access control systems. Most, if not all, of these proposals impose restrictions on the implementation of access control systems, thereby limiting the type of authorization requests that can be processed or the structure of the authorization policies that can be specified. In this paper, we develop a formal characterization of the features of an access control model that imposes few restrictions of this nature. Our characterization is intended to be a generic framework for access control, from which we may derive access control models and reason about the properties of those models. In this paper, we consider the properties of monotonicity and completeness, the first being particularly important for attributebased access control systems. XACML, an XML-based language and architecture for attribute-based access control, is neither monotonic nor complete. Using our framework, we define attribute-based access control models, in the style of XACML, that are, respectively, monotonic and complete.
منابع مشابه
The Entity Labeling Pattern for Modeling Operating Systems Access Control
To meet tightening security requirements, modern operating systems enforce mandatory access control based on formal security policies. To ensure the critical property of policy correctness, formal methods and models for both their specification and verification are used. The variety of these approaches reflects the diversity and heterogeneity of policy semantics, which makes policy engineering ...
متن کاملTowards a Uniform Framework for Dynamic Analysis of Access Control Models
Security-critical system requirements are increasingly enforced through mandatory access control systems. These systems are controlled by security policies, highly sensitive system components, which emphasizes the paramount importance of formally verified security properties regarding policy correctness. For the class of safety-properties, addressing potential dynamic right proliferation, a num...
متن کاملTowards an Integrated Formal Analysis for Security and Trust
We aim at defining an integrated framework for the specification and (automated) analysis for security and trust in complex and dynamic scenarios. In particular, we show how the same machinery used for the formal verification of security protocols may be used to analyze access control policies based on trust management.
متن کاملTowards a Reusable Evaluation Framework for Ontology based biomedical Systems Integration
Evaluation of ontology based integrated biomedical systems is important for them to find wide adoption and reuse in distributed computing environments that facilitate information exchange and knowledge generation in biomedicine. The review reveals many approaches to information systems and ontology based evaluation with standards, none of which are generic enough for use in all situations. It a...
متن کاملTowards Proving Security in the Presence of Large Untrusted Components
This paper proposes a generalized framework to build large, complex systems where security guarantees can be given for the overall system’s implementation. The work builds on the formally proven correct seL4 microkernel and on its fine-grained access control. This access control mechanism allows large untrusted components to be isolated in a way that prevents them from violating a defined secur...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- CoRR
دوره abs/1204.2342 شماره
صفحات -
تاریخ انتشار 2012