Access Control with Non-deterministic and Probabilistic Attribute Retrieval
نویسندگان
چکیده
Attribute Based Access Control (ABAC) is becoming the reference model for the specification and evaluation of access control policies. In ABAC policies and access requests are defined in terms of pairs attribute names/values. The applicability of an ABAC policy to a request is determined by matching the attributes in the request with the attributes in the policy. Some languages supporting ABAC, such as PTaCL or XACML 3.0, take into account the possibility that some attributes values might not be correctly retrieved when the request is evaluated, and use complex decisions, usually describing all possible evaluation outcomes, to account for missing attributes. In this paper, we argue that the problem of missing attributes in ABAC can be seen as a nondeterministic attribute retrieval process, and we show that the current evaluation mechanism in PTaCL or XACML can return a complex decision that does not necessarily match with the actual possible outcomes. This, however, is problematic for the enforcing mechanism, which needs to resolve the complex decision into a conclusive one. We propose a new evaluation mechanism, explicitly based on non-deterministic attribute retrieval for a given request. We extend this mechanism to probabilistic attribute retrieval and implement a probabilistic policy evaluation mechanism for PTaCL in PRISM, a probabilistic model-checker.
منابع مشابه
Attribute-based Access Control for Cloud-based Electronic Health Record (EHR) Systems
Electronic health record (EHR) system facilitates integrating patients' medical information and improves service productivity. However, user access to patient data in a privacy-preserving manner is still challenging problem. Many studies concerned with security and privacy in EHR systems. Rezaeibagha and Mu [1] have proposed a hybrid architecture for privacy-preserving accessing patient records...
متن کاملRobust optimal multi-objective controller design for vehicle rollover prevention
Robust control design of vehicles addresses the effect of uncertainties on the vehicle’s performance. In present study, the robust optimal multi-objective controller design on a non-linear full vehicle dynamic model with 8-degrees of freedom having parameter with probabilistic uncertainty considering two simultaneous conflicting objective functions has been made to prevent the rollover. The obj...
متن کاملA combination of semantic and attribute-based access control model for virtual organizations
A Virtual Organization (VO) consists of some real organizations with common interests, which aims to provide inter organizational associations to reach some common goals by sharing their resources with each other. Providing security mechanisms, and especially a suitable access control mechanism, which enforces the defined security policy is a necessary requirement in VOs. Since VO is a complex ...
متن کاملOptimizing of an Integrated Production-Distribution System with Probabilistic Parameters in a Multi-Level Supply Chain Network Considering the Backorder
One of the main arguments in the supply chain is integrated production-distribution planning. Integrated production and distribution of products in a supply chain plays an important role in reducing the costs of the chain. In this paper, a mathematical model for the integrated production-distribution problem in a three-level supply chain, including manufacturing plants, distribution centers and...
متن کاملA Probabilistic Topology Unaware TDMA Medium Access Control Policy for Ad Hoc Environments
The design of an efficient Medium Access Control (MAC) is challenging in ad-hoc networks where users can enter, leave or move inside the network without any need for prior configuration. Chlamtac and Farago have proposed a topology unaware TDMA-based scheme, suitable for ad-hoc networks, while Ju and Li have proposed an enhanced version that maximizes the minimum guaranteed throughput. Both app...
متن کامل