• DocumentCode
    3288158
  • Title

    A provenance-based access control model

  • Author

    Park, Jaehong ; Nguyen, Dang ; Sandhu, Ravi

  • Author_Institution
    Inst. for Cyber Security, Univ. of Texas at San Antonio, San Antonio, TX, USA
  • fYear
    2012
  • fDate
    16-18 July 2012
  • Firstpage
    137
  • Lastpage
    144
  • Abstract
    Existence of data provenance information in a system raises at least two security-related issues. One is how provenance data can be used to enhance security in the system and the other is how to protect provenance data which might be more sensitive than the data itself. Recent data provenance-related access control literature mainly focuses on the latter issue of protecting provenance data. In this paper, we propose a novel provenance-based access control model that addresses the former objective. Using provenance data for access control to the underlying data facilitates additional capabilities beyond those available in traditional access control models. We utilize a notion of dependency as the key foundation for access control policy specification. Dependency-based policy provides simplicity and effectiveness in policy specification and access control administration. We show our model can support dynamic separation of duty, workflow control, origin-based control, and object versioning. The proposed model identifies essential components and concepts and provides a foundational base model for provenance-based access control. We further discuss possible extensions of the proposed base model for enhanced access controls.
  • Keywords
    authorisation; information science; access control administration; access control policy specification; data provenance information; dependency notion; dependency-based policy; dynamic duty separation; object versioning; origin-based control; provenance data protection; provenance-based access control model; security enhancement; workflow control; Authorization; Computational modeling; Data models; Grammar; History;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Privacy, Security and Trust (PST), 2012 Tenth Annual International Conference on
  • Conference_Location
    Paris
  • Print_ISBN
    978-1-4673-2323-9
  • Electronic_ISBN
    978-1-4673-2325-3
  • Type

    conf

  • DOI
    10.1109/PST.2012.6297930
  • Filename
    6297930