Back to Search
Start Over
Admin-CBAC
- Source :
- CODASPY
- Publication Year :
- 2020
- Publisher :
- ACM, 2020.
-
Abstract
- We present Admin-CBAC, an administrative model for Category- Based Access Control (CBAC). Since most of the access control models in use nowadays are instances of CBAC, in particular the popular RBAC and ABAC models, from Admin-CBAC we derive administrative models for RBAC and ABAC too. We define Admin- CBAC using Barker's metamodel, and use its axiomatic semantics to derive properties of administrative policies. Using an abstract operational semantics for administrative actions, we show how properties (such as safety, liveness and effectiveness of policies) and constraints (such as separation of duties) can be checked, and discuss the impact of policy changes. Although the most interesting properties of policies are generally undecidable in dynamic access control models, we identify particular cases where reachability based properties are decidable and can be checked using our operational semantics, generalising previous results for RBAC and ABACalpha.
- Subjects :
- 021110 strategic, defence & security studies
Computer science
business.industry
Separation of duties
Programming language
010102 general mathematics
Liveness
0211 other engineering and technologies
Access control
02 engineering and technology
computer.software_genre
01 natural sciences
Operational semantics
Axiomatic semantics
Decidability
Metamodeling
Role-based access control
0101 mathematics
business
computer
Subjects
Details
- Database :
- OpenAIRE
- Journal :
- Proceedings of the Tenth ACM Conference on Data and Application Security and Privacy
- Accession number :
- edsair.doi...........d2bb0cd4878a249f53e598db169eff62
- Full Text :
- https://doi.org/10.1145/3374664.3375725