Dynamic delegation based on temporal and nonmonotonic description logic

Ouarda Bettaz, Narhimène Boustia, A. Mokhtari
{"title":"Dynamic delegation based on temporal and nonmonotonic description logic","authors":"Ouarda Bettaz, Narhimène Boustia, A. Mokhtari","doi":"10.1109/ISPS.2015.7244994","DOIUrl":null,"url":null,"abstract":"Access control provides the mean of restricting the access to a computer system by checking whether a legitimate user has the rights to perform certain actions on the resources. Therefore it should rely on flexible administrative mechanism. An important component of the administrative mechanism is delegation. Delegation is the process of granting a specific authorization from a user to another user of the same system to carry out some functions on his behalf. The delegation, although widely used, is modeled in very little security policies because this concept is very complex. What we tried to do in this work is to redefine delegation for OrBAC using description logic. OrBAC is an access control model; it provides the mean to specify contextual authorizations, which facilitates modeling the features of the delegation such as temporary delegation, multiple delegation, revocation, etc. The description logic that we use for the re-formalization process is T-JClassicδϵ. This logic is a temporal nonmonotonic description logic, it gives the mean to specify nonmonotonic authorizations, and a better representation of the temporal aspects specific to a given delegation. This new representation augments the expressivity of the model and therefore it facilitates even more the representation and the management of the delegation characteristics.","PeriodicalId":165465,"journal":{"name":"2015 12th International Symposium on Programming and Systems (ISPS)","volume":"43 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-04-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 12th International Symposium on Programming and Systems (ISPS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISPS.2015.7244994","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Access control provides the mean of restricting the access to a computer system by checking whether a legitimate user has the rights to perform certain actions on the resources. Therefore it should rely on flexible administrative mechanism. An important component of the administrative mechanism is delegation. Delegation is the process of granting a specific authorization from a user to another user of the same system to carry out some functions on his behalf. The delegation, although widely used, is modeled in very little security policies because this concept is very complex. What we tried to do in this work is to redefine delegation for OrBAC using description logic. OrBAC is an access control model; it provides the mean to specify contextual authorizations, which facilitates modeling the features of the delegation such as temporary delegation, multiple delegation, revocation, etc. The description logic that we use for the re-formalization process is T-JClassicδϵ. This logic is a temporal nonmonotonic description logic, it gives the mean to specify nonmonotonic authorizations, and a better representation of the temporal aspects specific to a given delegation. This new representation augments the expressivity of the model and therefore it facilitates even more the representation and the management of the delegation characteristics.
基于时序非单调描述逻辑的动态委托
访问控制通过检查合法用户是否有权对资源执行某些操作来限制对计算机系统的访问。因此,它应该依靠灵活的管理机制。行政机制的一个重要组成部分是授权。授权是将一个用户的特定授权授予同一系统的另一个用户以代表他执行某些功能的过程。委托虽然被广泛使用,但由于这个概念非常复杂,因此很少在安全策略中建模。我们在这项工作中尝试做的是使用描述逻辑重新定义OrBAC的委托。OrBAC是一个访问控制模型;它提供了指定上下文授权的方法,这有助于对委托的特性(如临时委托、多重委托、撤销等)进行建模。我们用于重新形式化过程的描述逻辑是t - jclassic δ λ。该逻辑是一种时间非单调描述逻辑,它提供了指定非单调授权的方法,并更好地表示特定于给定委托的时间方面。这种新的表示方式增强了模型的表达能力,因此更有利于委托特征的表示和管理。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信