Extended ReBAC Administrative models with cascading revocation and provenance support

9Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.

Abstract

Relationship-based access control (ReBAC) has been widely studied and applied in the domain of online social networks, and has since been extended to domains beyond social. Us-ing ReBAC itself to manage ReBAC also becomes a natural research frontier, where we have two ReBAC administrative models proposed recently by Rizvi et al. [30] and Stoller [33]. In this paper, we extend these two ReBAC administrative models in order to apply ReBAC beyond online social net-works, particularly where edges can have dependencies with each other and authorization for certain administrative oper-Ations requires provenance information. Basically, our policy specifications adopt the concepts of enabling precondition and applicability preconditions from Rizvi et al. [30]. Then, we address several issues that need to be considered in order to properly execute operation effects, such as cascading re-vocation and integrity constraints on the relationship graph. With these extended features, we show that our administra-Tive models can provide the administration capability of the MT-RBAC model originally designed for multi-Tenant col-laborative cloud systems [34].

Cite

CITATION STYLE

APA

Cheng, Y., Bijon, K., & Sandhu, R. (2016). Extended ReBAC Administrative models with cascading revocation and provenance support. In Proceedings of ACM Symposium on Access Control Models and Technologies, SACMAT (Vol. 06-08-June-2016, pp. 161–170). Association for Computing Machinery. https://doi.org/10.1145/2914642.2914655

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free