DocumentCode :
2554466
Title :
Foundations of Logic-Based Trust Management
Author :
Becker, M.Y. ; Russo, A. ; Sultana, N.
Author_Institution :
Microsoft Res., Cambridge, UK
fYear :
2012
fDate :
20-23 May 2012
Firstpage :
161
Lastpage :
175
Abstract :
Over the last 15 years, many policy languages have been developed for specifying policies and credentials under the trust management paradigm. What has been missing is a formal semantics - in particular, one that would capture the inherently dynamic nature of trust management, where access decisions are based on the local policy in conjunction with varying sets of dynamically submitted credentials. The goal of this paper is to rest trust management on a solid formal foundation. To this end, we present a model theory that is based on Kripke structures for counterfactual logic. The semantics enjoys compositionality and full abstraction with respect to a natural notion of observational equivalence between trust management policies. Furthermore, we present a corresponding Hilbert-style axiomatization that is expressive enough for reasoning about a system´s observables on the object level. We describe an implementation of a mechanization of the proof theory, which can be used to prove non-trivial meta-theorems about trust management systems, as well as analyze probing attacks on such systems. Our benchmark results show that this logic-based approach performs significantly better than the only previously available, ad-hoc analysis method for probing attacks.
Keywords :
authorisation; formal logic; theorem proving; trusted computing; Hilbert-style axiomatization; Kripke structures; access decisions; compositionality; counterfactual logic; dynamic credentials; formal semantics; local policy; logic-based trust management; mechanization; model theory; nontrivial meta-theorem proving; policy languages; probing attack analysis; proof theory; Cognition; Concrete; Context; Probes; Semantics; Standards; Syntactics; Datalog; access control; counterfactual logic; credential; policy language; probing attack; semantics; trust management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security and Privacy (SP), 2012 IEEE Symposium on
Conference_Location :
San Francisco, CA
ISSN :
1081-6011
Print_ISBN :
978-1-4673-1244-8
Electronic_ISBN :
1081-6011
Type :
conf
DOI :
10.1109/SP.2012.20
Filename :
6234411
Link To Document :
بازگشت