A Category-Based Model for ABAC

被引:4
作者
Fernandez, Maribel [1 ]
Thuraisingham, Bhavani [2 ]
机构
[1] Kings Coll London, London, England
[2] Univ Texas Dallas, Richardson, TX 75083 USA
来源
PROCEEDINGS OF THE THIRD ACM WORKSHOP ON ATTRIBUTE-BASED ACCESS CONTROL (ABAC'18) | 2018年
关键词
ACCESS-CONTROL;
D O I
10.1145/3180457.3183326
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In Attribute-Based Access Control (ABAC) systems, access to resources is controlled by evaluating rules against the attributes of the user and the object involved in the access request, as well as the values of the relevant attributes from the environment. This is a powerful concept: ABAC is able to enforce DAC and RBAC policies, as well as more general, dynamic access control policies, where the decision to grant or deny an access request is based on the system's state. However, in its current definition, ABAC does not lend itself well to some operations, such as review queries, and it is in general more costly to specify and maintain than simpler systems such as RBAC. To address these issues, in this paper we propose a formal model of ABAC based on the notion of a category that underlies the general category-based metamodel of access control (CBAC). Our proposed approach adds structure to ABAC, so that policies are easier to design and understand, review queries become easy to evaluate, and simple systems such as RBAC can be implemented as instances of ABAC without additional costs.
引用
收藏
页码:32 / 34
页数:3
相关论文
共 19 条
[1]  
[Anonymous], 2011, 22 INT C REWR TECHN
[2]  
[Anonymous], 1998, Term Rewriting and All That
[3]  
Barker S, 2009, SACMAT'09: PROCEEDINGS OF THE 14TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, P187, DOI 10.1145/1542207.1542238
[4]  
Bertolissi C., 2008, P 10 ACM SIGPLAN S P
[5]  
Bertolissi C., 2007, LECT NOTES COMPUTER, V4602
[6]   A metamodel of access control for distributed environments: Applications and properties [J].
Bertolissi, Clara ;
Fernandez, Maribel .
INFORMATION AND COMPUTATION, 2014, 238 :187-207
[7]  
Bertolissi C, 2010, LECT NOTES COMPUT SC, V5965, P140, DOI 10.1007/978-3-642-11747-3_11
[8]  
Clavel M, 2003, LECT NOTES COMPUT SC, V2706, P76
[9]  
Dougherty DJ, 2007, LECT NOTES COMPUT SC, V4734, P578
[10]  
Dougherty DJ, 2006, LECT NOTES ARTIF INT, V4130, P632