Security analysis and validation for access control in multi-domain environment based on risk

4Citations
Citations of this article
2Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Access control system is often described as a state transition system. Given a set of access control policies, a general safety requirement in such a system is to determine whether a desirable property is satisfied in all the reachable states. In this paper, we propose to use security analysis techniques to maintain desirable security properties in the Multi-domain Environment based on risk model (MDR2BAC). We give a precise definition of security analysis problems in MDR2BAC, which is more general than safety analysis that is studied in single-domain. We show the process of dynamic permission adjustment in multi-domain environment, and illustrate two classes of problems in the process which can be reduced to similar analysis in the RT[←,∩] role-based trust-management language, thereby establishing an interesting relationship between MDR2BAC and the RT framework. The reduction gives efficient algorithms for answering most kinds of queries in the two stages of dynamic adjustment permissions. © Springer-Verlag Berlin Heidelberg 2010.

Cite

CITATION STYLE

APA

Tang, Z., Zhang, S., Li, K., & Feng, B. (2010). Security analysis and validation for access control in multi-domain environment based on risk. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 6047 LNCS, pp. 201–216). https://doi.org/10.1007/978-3-642-12827-1_15

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free