
Open access
Date
2014Type
- Report
ETH Bibliography
yes
Altmetrics
Abstract
Formal foundations for access control policies with both authority delegation and policy composition operators are partial and limited. Correctness guarantees cannot therefore be formally stated and verified for decentralized composite access control systems, such as those based on XACML 3. To address this problem we develop a formal policy language BelLog that can express both delegation and composition operators. We illustrate, through examples, how BelLog can be used to specify practical policies. Moreover, we present an analysis framework for reasoning about BelLog policies and we give decidability and complexity results for policy entailment and policy containment in BelLog. Show more
Permanent link
https://doi.org/10.3929/ethz-a-010045530Publication status
publishedPublisher
ETHSubject
ACCESS CONTROL (OPERATING SYSTEMS); NETZWERKÜBERWACHUNG + NETZWERKADMINISTRATION (COMPUTERSYSTEME); NETWORK MONITORING (COMPUTER SYSTEMS); ZUGRIFFSKONTROLLE (BETRIEBSSYSTEME)Organisational unit
02150 - Dep. Informatik / Dep. of Computer Science03634 - Basin, David / Basin, David
More
Show all metadata
ETH Bibliography
yes
Altmetrics