On transformation of authorization policies

作者:

Highlights:

摘要

In this paper, we propose a logic based approach to specify and to reason about transformation of authorization policies. The authorization policy is specified using a policy base which comprises a finite set of facts and access constraints. We define the structure of the policy transformation and employ a model-based semantics to perform the transformation under the principle of minimal change. Furthermore, we extend model-based semantics by introducing preference ordering to resolve possible conflicts during transformation of policies. We also discuss the implementation of the model-based transformation approach and analyse the complexity of the algorithms introduced. Our system is able to represent both implicit and incomplete authorization requirements and reason about nonmonotonic properties.

论文关键词:Logic based specification,Security,Authorization policy,Transformations

论文评审过程:Received 27 September 2001, Revised 15 January 2002, Accepted 9 July 2002, Available online 15 November 2002.

论文官网地址:https://doi.org/10.1016/S0169-023X(02)00194-5