arrow
Return

Modeling adaptive access control policies using answer set programming

delete2019-02-01
delete8
delete
OA
AI
S
Sara Sartoli
A
Akbar Siami Namin *
DOI:10.1016/j.jisa.2018.10.007delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Many of the existing management platforms such as pervasive computing systems implement policies that depend on dynamic operational environment changes. Existing formal approaches for automatically enforcing access control policies are primarily expressed in conventional logic programming, also known as monotonic logics, e.g., First Order Logic (FOL). The major issue with monotonic logics is that they are not devised to invalidate initial believes in the light of further observations. This limitation makes these traditional logical approaches less suitable for modeling and analyzing context-aware access control policies, where exceptional policies are introduced incrementally and adaptively during runtime. The inability to invalidate initial policies when an exception needs to be enforced might result in inconsistencies and violations that need to be resolved manually by human entities. To address the problems with conventional logical approaches and more importantly prevent such inconsistencies, this paper presents a non-monotonic logic-based reasoning scheme for modeling and analyzing adaptive access control policies. In the proposed formalism, unavailable context data and incomplete access control policies can be explicitly expressed. To do so, the paper distinguishes three kinds of policies: default, context-dependent and exception policies. The proposed formalism is based on Answer Set Programming (ASP), a non-monotonic logic programming language that allows elegant representation of unavailability of context data in adaptive systems. We devise non-monotonic policy inference rules such that, when exception policies are defined, they take precedence over default and context-dependent policies automatically. The results of two case studies are reported to demonstrate the feasibility of the proposed policy representation scheme compared to the Organizational-Based Access Control (OrBAC) model. (C) 2018 Elsevier Ltd. All rights reserved.
Keywords:
Access control
Inference mechanism
Answer set programming
Policies
Exception handling
Conflict
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Journal of Information Security and Applications cover
Journal of Information Security and Applications
IF:
3.7
Papers:
1.9K
Citations:
4.9K

Organization

U
University of North Georgia
Scholars:
292
Papers: 251
Citations: 272
Texas Tech University System cover
Texas Tech University System
Scholars:
1.5W
Papers: 1.3W
Citations: 15