School of Computing

Automated Decomposition of Access Control Policies

L Su, DW Chadwick, A Basden, and JA Cunningham

In Proceeds of 6th IEEE International Workshop on Policies for Distributed Systems and Networks, pages 182-196, Stockholm, Sweden, June 2005.

Abstract

Modern dynamic distributed information systems need access control policies to address controlling access to multiple resources that are distributed. The resources may be considered as a single abstract hierarchical resource. An access control policy at a high level should be able to define who is allowed to use the resources. At lower levels, the policy will address controlling access to concrete resources. By modelling the resource hierarchy, it is possible that low level policies can be automatically produced from the high level policy. These low level policies can then be distributed to the concrete resources that use an existing policy based access control decision system so that the high level policy can be enforced throughout the system. In this paper a model for representing and refining high level policies is presented. Other relevant issues and examples for demonstrating the capability of the policy decomposition

Download publication 193 kbytes (PDF)

Bibtex Record

@inproceedings{2290,
author = {L Su and DW Chadwick and A Basden and JA Cunningham},
title = {{Automated Decomposition of Access Control Policies}},
month = {June},
year = {2005},
pages = {182-196},
keywords = {determinacy analysis, Craig interpolants},
note = {},
doi = {},
url = {http://www.cs.kent.ac.uk/pubs/2005/2290},
    publication_type = {inproceedings},
    submission_id = {4786_1131549215},
    booktitle = {Proceeds of 6th IEEE International Workshop on Policies for Distributed Systems and Networks},
    address = {Stockholm, Sweden},
}

School of Computing, University of Kent, Canterbury, Kent, CT2 7NF

Enquiries: +44 (0)1227 824180 or contact us.

Last Updated: 21/03/2014