DocumentCode
2928687
Title
A research challenge in modeling access control policies: Modeling recommendations
Author
El Kalam, Anas Abou
Author_Institution
IRIT - INPT / ENSEEIHT, Univ. de Toulouse, Toulouse
fYear
2008
fDate
3-6 June 2008
Firstpage
263
Lastpage
270
Abstract
Security Policies should be well-defined in any serious security study and should capture all the requirements of the targeted system. However, while current and emergent applications become more and more complex, most of the existing security policies and models only consider a yes/no response to the access requests. Consequently, modeling, formalizing and implementing permissions, obligations and prohibitions do not cover the richness of all the possible scenarios. In fact, many applications have access rules with the recommendation access modality. In this paper we focus on the problem of security policies formalization. The aim is to provide a generic domain- independent approach. In order to achieve these goals, we have chosen a logic-based approach that enhances the Deontic logic (the logic of permissions, obligations and prohibitions) with the recommendation and inadvisable access modalities. We thus present a new logical framework including a Recommendation Specification Language (RSL) as well as the necessary axiomatic to derive rules and to reason (e.g., query, verify) on the security policy. Our logical framework can thus be used by security administrators to automatically derive consequences of their policies.
Keywords
authorisation; formal logic; specification languages; access control policy modeling; deontic logic; generic domain-independent approach; logic-based approach; recommendation access modality; recommendation specification language; security policy formalization; Access control; Current control; Data security; Guidelines; Information security; Legislation; Logic; Medical services; Permission; Specification languages; Deontic logic; Information systems security; access control models; security policies;
fLanguage
English
Publisher
ieee
Conference_Titel
Research Challenges in Information Science, 2008. RCIS 2008. Second International Conference on
Conference_Location
Marrakech
Print_ISBN
978-1-4244-1677-6
Electronic_ISBN
978-1-4244-2273-9
Type
conf
DOI
10.1109/RCIS.2008.4632115
Filename
4632115
Link To Document