Access Control Policy Translation and Verification within Heterogeneous Data Federations

被引:1
|
作者
Leighton, Gregory [1 ]
Barbosa, Denilson [1 ]
机构
[1] Univ Alberta, Dept Comp Sci, Edmonton, AB, Canada
来源
SACMAT 2010: PROCEEDINGS OF THE 15TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES | 2010年
关键词
Access Control; Relational Databases; XML; XACML;
D O I
10.1145/1809842.1809871
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Data federations provide seamless access to multiple heterogeneous and autonomous data sources pertaining to a large organization. As each source database defines its own access control policies for a set of local identities, enforcing such policies across the federation becomes a challenge. In this paper, we first consider the problem of translating existing access control policies defined over source databases in a manner that allows the original semantics to be observed, while becoming applicable across the entire data federation. We show that such a translation is always possible, and provide an algorithm for automating the translation. We then show that verifying that a translated policy obeys the semantics of the original access control policy defined over a source database is intractable, even under restrictive scenarios. Finally, we describe a practical algorithmic framework for translating relational access control policies into their XML equivalent, expressed in the eXtensible Access Control Markup Language.
引用
收藏
页码:173 / 182
页数:10
相关论文
共 50 条
  • [1] Access Control Policy Translation, Verification, and Minimization within Heterogeneous Data Federations
    Leighton, Gregory
    Barbosa, Denilson
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2011, 14 (03)
  • [2] Access Control Policy Verification
    Hu, Vincent C.
    Kuhn, Rick
    COMPUTER, 2016, 49 (12) : 80 - 83
  • [3] General Methods for Access Control Policy Verification
    Hu, Vincent C.
    Kuhn, D. Richard
    PROCEEDINGS OF 2016 IEEE 17TH INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION (IEEE IRI), 2016, : 315 - 323
  • [5] CHALLENGES FOR ACCESS CONTROL IN KNOWLEDGE FEDERATIONS
    Evdokimov, Sergei
    Fabian, Benjamin
    Kunz, Steffen
    KMIS 2009: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON KNOWLEDGE MANAGEMENT AND INFORMATION SHARING, 2009, : 224 - 229
  • [6] Access control for semantic data federations in industrial product-lifecycle management
    Fabian, Benjamin
    Kunz, Steffen
    Konnegen, Marcel
    Mueller, Sebastian
    Guenther, Oliver
    COMPUTERS IN INDUSTRY, 2012, 63 (09) : 930 - 940
  • [7] Access control for web data: models and policy languages
    Carminati, Barbara
    Ferrari, Elena
    Thuraisingham, Bhavani
    ANNALS OF TELECOMMUNICATIONS, 2006, 61 (3-4) : 245 - 266
  • [8] Access control for web data: Models and policy languages
    Universita dell'Insubria, Dipartimento di Scienze della Cultura, Politiche e Informazione, Via Carloni, 78, 22100 Como, Italy
    不详
    Ann Telecommun, 2006, 3-4 (245-266): : 245 - 266
  • [9] A Distributed Access Control System for Cloud Federations
    Alansari, Shorouq
    Paci, Federica
    Sassone, Vladimiro
    2017 IEEE 37TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS 2017), 2017, : 2131 - 2136
  • [10] Evaluating the Capability and Performance of Access Control Policy Verification Tools
    Li, Ang
    Li, Qinghua
    Hu, Vincent C.
    Di, Jia
    2015 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM 2015), 2015, : 366 - 371