Show simple item record

dc.contributor.author
Tsankov, Petar
dc.contributor.author
Torabi Dashti, Mohammad
dc.contributor.author
Basin, David
dc.date.accessioned
2020-07-13T10:58:00Z
dc.date.available
2017-06-12T09:04:20Z
dc.date.available
2020-05-15T12:49:02Z
dc.date.available
2020-07-13T10:58:00Z
dc.date.issued
2016-05-05
dc.identifier.uri
http://hdl.handle.net/20.500.11850/118353
dc.description.abstract
Access-control requirements for physical spaces, like office buildings and airports, are best formulated from a global viewpoint in terms of system-wide requirements. For example, "there is an authorized path to exit the building from every room." In contrast, individual access-control components, such as doors and turnstiles, can only enforce local policies, specifying when the component may open. In practice, the gap between the system-wide, global requirements and the many local policies is bridged manually, which is tedious, error-prone, and scales poorly. We propose a framework to automatically synthesize local access control policies from a set of global requirements for physical spaces. Our framework consists of an expressive language to specify both global requirements and physical spaces, and an algorithm for synthesizing local, attribute-based policies from the global specification. We empirically demonstrate the framework's effectiveness on three substantial case studies. The studies demonstrate that access control synthesis is practical even for complex physical spaces, such as airports, with many interrelated security requirements.
en_US
dc.language.iso
en
en_US
dc.publisher
Cornell University
en_US
dc.title
Access Control Synthesis for Physical Spaces
en_US
dc.type
Working Paper
ethz.journal.title
arXiv
ethz.pages.start
1605.01769
en_US
ethz.size
20 p.
en_US
ethz.identifier.arxiv
1605.01769
ethz.publication.place
Ithaca, NY
en_US
ethz.publication.status
published
en_US
ethz.leitzahl
ETH Zürich::00002 - ETH Zürich::00012 - Lehre und Forschung::00007 - Departemente::02150 - Dep. Informatik / Dep. of Computer Science::02660 - Institut für Informationssicherheit / Institute of Information Security::03634 - Basin, David / Basin, David
en_US
ethz.leitzahl.certified
ETH Zürich::00002 - ETH Zürich::00012 - Lehre und Forschung::00007 - Departemente::02150 - Dep. Informatik / Dep. of Computer Science::02660 - Institut für Informationssicherheit / Institute of Information Security::03634 - Basin, David / Basin, David
ethz.relation.isPreviousVersionOf
20.500.11850/120069
ethz.date.deposited
2017-06-12T09:08:45Z
ethz.source
ECIT
ethz.identifier.importid
imp5936548b9183a26916
ethz.ecitpid
pub:180305
ethz.eth
yes
en_US
ethz.availability
Metadata only
en_US
ethz.rosetta.installDate
2017-07-14T17:42:31Z
ethz.rosetta.lastUpdated
2022-03-29T02:38:37Z
ethz.rosetta.versionExported
true
ethz.COinS
ctx_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:journal&rft.atitle=Access%20Control%20Synthesis%20for%20Physical%20Spaces&rft.jtitle=arXiv&rft.date=2016-05-05&rft.spage=1605.01769&rft.au=Tsankov,%20Petar&Torabi%20Dashti,%20Mohammad&Basin,%20David&rft.genre=preprint&
 Search print copy at ETH Library

Files in this item

FilesSizeFormatOpen in viewer

There are no files associated with this item.

Publication type

Show simple item record