...
首页> 外文期刊>ACM Transaction on Information and System Security >Access Control via Belnap Logic: Intuitive, Expressive, and Analyzable Policy Composition
【24h】

Access Control via Belnap Logic: Intuitive, Expressive, and Analyzable Policy Composition

机译:通过Belnap Logic进行访问控制:直观,富有表现力和可分析的策略组合

获取原文
获取原文并翻译 | 示例

摘要

Access control to IT systems increasingly relies on the ability to compose policies. Hence there is benefit in any framework for policy composition that is intuitive, formal (and so "analyzable" and "implementable"), expressive, independent of specific application domains, and yet able to be extended to create domain-specific instances. Here we develop such a framework based on Belnap logic. An access-control policy is interpreted as a four-valued predicate that maps access requests to either grant, deny, conflict, or unspecified - the four values of the Belnap bilattice. We define an expressive access-control policy language PBel, having composition operators based on the operators of Belnap logic. Natural orderings on policies are obtained by lifting the truth and information orderings of the Belnap bilattice. These orderings lead to a query language in which policy analyses, for example, conflict freedom, can be specified. Policy analysis is supported through a reduction of the validity of policy queries to the validity of propositional formulas on predicates over access requests. We evaluate our approach through firewall policy and RBAC policy examples, and discuss domain-specific and generic extensions of our policy language.
机译:对IT系统的访问控制越来越依赖于组合策略的能力。因此,任何直观,正式(因而“可分析”和“可实现”),表现力强,独立于特定应用程序域,并且能够扩展以创建特定于域的实例的策略组合框架都将受益。在这里,我们基于Belnap逻辑开发了这样的框架。访问控制策略被解释为一个四值谓词,该谓词将访问请求映射为Belnap bilattice的四个值,即授予,拒绝,冲突或未指定。我们定义了一种表达性的访问控制策略语言PBel,它具有基于Belnap逻辑运算符的组合运算符。通过解除Belnap bilattice的真相和信息顺序,可以获得自然的政策顺序。这些排序导致查询语言可以指定策略分析(例如,冲突自由)。通过将策略查询的有效性降低为基于访问请求的谓词的命题公式的有效性,可以支持策略分析。我们通过防火墙策略和RBAC策略示例评估我们的方法,并讨论策略语言的特定于域和通用的扩展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号