DocumentCode :
3594905
Title :
Research on multilevel security access control policy processing method
Author :
Junshe Wang ; Shengjuan Liu ; Hongbin Zhang ; Jiang Chang
Author_Institution :
Sch. of Inf. Sci. & Eng., Hebei Univ. of Sci. & Technol., Shijiazhuang, China
fYear :
2014
Firstpage :
180
Lastpage :
184
Abstract :
Access control is one of the most important means to protect the resources of multilevel security systems. So to make sure the authorization of multilevel security access control can be legally enforced, the access control policies must be correct and complete. Based on the implicit hierarchical relations between subjects and objects in multilevel security access control systems, this paper gives a method to build a unified directed acyclic graph(DAG) model (including both subjects and objects), using the partial orders based on sets. This method is easier to realize and is more utility for designing the access control model. Also based on partially ordered set, this paper proposes the algorithms for detecting policy conflicts and incomplete policies, which is embedding in the process of building DAG model. In the end, this paper verifies the correctness of the algorithm by experiment.
Keywords :
authorisation; directed graphs; DAG model; implicit hierarchical relations; multilevel security access control policy processing method; partially ordered set; policy conflict detection; unified directed acyclic graph model; Multilevel security; access control; conflict detection; directed acyclic graph;
fLanguage :
English
Publisher :
iet
Conference_Titel :
Information and Network Security, ICINS 2014 - 2014 International Conference on
Print_ISBN :
978-1-84919-909-4
Type :
conf
DOI :
10.1049/cp.2014.1284
Filename :
7133815
Link To Document :
بازگشت