Representation and reasoning on ORBAC: Description logic with defaults and exceptions approach

被引:5
作者
Boustia, Narhimene [1 ]
Mokhtari, Aicha [2 ]
机构
[1] USDB, Dept Comp Sci, Blida, Algeria
[2] USTHB, Dept Comp Sci, Algiers, Algeria
来源
ARES 2008: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON AVAILABILITY, SECURITY AND RELIABILITY | 2008年
关键词
security; ORBAC; description logic; exception; default;
D O I
10.1109/ARES.2008.144
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In the Organization Based Access Control (ORBAC) model, to express security policy, it is necessary to make possible the system know which are the privileges of each user. The definition of permission should not be static, but it must depend on the requirement of the system, rules should be dynamic, depending on the context. Context is used to specify the concrete circumstances where user is given role permissions to perform activities on views. Formalization of ORBAC in a logical approach makes it feasible to reason about a specified policy and verifies its correctness. We propose a formal modelisation of ORBAC by the description logic language with default and exception AL(delta epsilon). We show how exception in information system security can be captured by AL(delta epsilon). We illustrate this approach by an example of a medical information system.
引用
收藏
页码:1008 / +
页数:2
相关论文
共 12 条
[1]  
[Anonymous], IEEE COMPUTER
[2]  
Baader F., 2002, DESCRIPTION LOGIC HD
[3]  
Bell D. E., 1976, ESDTR73306 MITRE COR
[4]  
Biba K. J., 1975, MTR3153 MITRE CORP
[5]  
COUPEY P, 1997, COMPUTATIONAL INTELL, V13
[6]  
CUPPENS F, 2003, 19 ANN COMP SEC APPL
[7]  
ELKALAM AA, 2003, IEEE 4 INT WORKSH PO
[8]  
LAMPSON B, 1971, 5 PRINC S INF SCI SY, P437
[9]  
NAPOLI A, 1997, 3314 INRIA
[10]  
NEBEL B, 1990, LECT NOTES COMPUTER, V422