首页> 外文会议>2011 Fifth IEEE International Conference on Semantic Computing >Automated Analysis of Semantic-Aware Access Control Policies: A Logic-Based Approach
【24h】

Automated Analysis of Semantic-Aware Access Control Policies: A Logic-Based Approach

机译:语义感知访问控制策略的自动分析:基于逻辑的方法

获取原文

摘要

As the number and sophistication of on-line applications increase, there is a growing concern on how access to sensitive resources (e.g., personal health records) is regulated. Since ontologies can support the definition of fine-grained policies as well as the combination of heterogeneous policies, semantic technologies are expected to play an important role in this context. But understanding the implications of the access control policies of the needed complexity goes beyond the ability of a security administrator. Automatic support to the analysis of access control policies is therefore needed. In this paper we present an automatic analysis technique for access control policies that reduces the reach ability problem for access control policies to satisfiability problems in a decidable fragment of first-order logic for which efficient solvers exist. We illustrate the application of our technique on an access control model inspired by a Personal Health Application of real-world complexity.
机译:随着在线应用程序的数量和复杂性的增加,人们越来越关注如何规范对敏感资源(例如个人健康记录)的访问。由于本体可以支持细粒度策略的定义以及异构策略的组合,因此语义技术有望在这种情况下发挥重要作用。但是,了解所需复杂性的访问控制策略的含义超出了安全管理员的能力。因此,需要自动支持访问控制策略的分析。在本文中,我们提出了一种访问控制策略的自动分析技术,该技术将访问控制策略的可到达性问题减少为存在有效求解器的可确定的一阶逻辑片段中的可满足性问题。我们举例说明了我们的技术在访问控制模型上的应用,该模型受现实世界中复杂性的“个人健康”应用启发。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号