Modelling Fine-Grained Access Control Policies in Grids

被引:1
作者
Aziz, Benjamin [1 ]
机构
[1] Univ Portsmouth, Sch Comp, Portsmouth PO1 3HE, Hants, England
关键词
Access control; Grid authorisation; Usage control;
D O I
10.1007/s10723-015-9351-x
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents an abstract specification of an enforcement mechanism of usage control for Grids, and verifies formally that such mechanism enforces UCON policies. Our technique is based on KAOS, a goal-oriented requirements engineering methodology with a formal LTL-based language and semantics. KAOS is used in a bottom-up form. We abstract the specification of the enforcement mechanism from current implementations of usage control for Grids. The result of this process is agent and operation models that describe the main components and operations of the enforcement mechanism. KAOS is used in top-down form by applying goal-refinement in order to refine UCON policies. The result of this process is a goal-refinement tree, which shows how a goal (policy) can be decomposed into sub-goals. Verification that a policy can be enforced is then equivalent to prove that a goal can be implemented by the enforcement mechanism represented by the agent and operation models.
引用
收藏
页码:477 / 493
页数:17
相关论文
共 30 条
[1]  
[Anonymous], P COMP INF SYST IND
[2]  
[Anonymous], 2004, J. Grid Comput
[3]  
[Anonymous], 2015, OBJECTOVER POWER TOO
[4]  
Bandara A. K., 2004, 5 IEEE WORKSH POL DI
[5]   Testing of PolPA-based usage control systems [J].
Bertolino, Antonia ;
Daoudagh, Said ;
Lonetti, Francesca ;
Marchetti, Eda ;
Martinelli, Fabio ;
Mori, Paolo .
SOFTWARE QUALITY JOURNAL, 2014, 22 (02) :241-271
[6]  
Chadwick D., 2008, TECHNICAL REPORT
[7]   A Proposal on Enhancing XACML with Continuous Usage Control Features [J].
Colombo, Maurizio ;
Lazouski, Aliaksandr ;
Martinelli, Fabio ;
Mori, Paolo .
GRIDS, P2P AND SERVICES COMPUTING, 2010, :133-+
[8]   The design, usage, and performance of GRUBER: A Grid Usage service level agreement based BrokERing infrastructure [J].
Dumitrescu C.L. ;
Raicu I. ;
Foster I. .
Journal of Grid Computing, 2007, 5 (1) :99-126
[9]   The anatomy of the grid: Enabling scalable virtual organizations [J].
Foster, I ;
Kesselman, C ;
Tuecke, S .
INTERNATIONAL JOURNAL OF HIGH PERFORMANCE COMPUTING APPLICATIONS, 2001, 15 (03) :200-222
[10]  
Janicke H., 2007, DERIVING ENFORCEMENT