Proactive identification and prevention of unexpected future rule conflicts in attribute based access control

0Citations
Citations of this article
3Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Attribute based access control (ABAC) provides an intuitive way for security administrators to express conditions (associated with status of objects) in access control policies; however, during the design and development of an ABAC system, new problems concerning the consistency and security of the ABAC system may emerge. In this paper, we report on two specific ABAC problems denoted as the "future rule conflicts" problem and the "object overlapping" problem, which we have recently identified in developing the ABAC system for a large research laboratory. We use real world examples to illustrate the negative impact of these two problems and present two novel algorithms for the identification and prevention of these problems. We give the correctness proof for both algorithm and apply these algorithms to the attribute based laboratory control (ABLC) system and the results are also reported. © 2010 Springer-Verlag Berlin Heidelberg.

Cite

CITATION STYLE

APA

Zha, D., Jing, J., Liu, P., Lin, J., & Jia, X. (2010). Proactive identification and prevention of unexpected future rule conflicts in attribute based access control. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 6019 LNCS, pp. 468–481). Springer Verlag. https://doi.org/10.1007/978-3-642-12189-0_41

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free