• DocumentCode
    589084
  • Title

    Relationship-Based Access Control for Online Social Networks: Beyond User-to-User Relationships

  • Author

    Yuan Cheng ; Jaehong Park ; Sandhu, Ravi

  • Author_Institution
    Inst. for Cyber Security, Univ. of Texas at San Antonio, San Antonio, TX, USA
  • fYear
    2012
  • fDate
    3-5 Sept. 2012
  • Firstpage
    646
  • Lastpage
    655
  • Abstract
    User-to-user (U2U) relationship-based access control has become the most prevalent approach for modeling access control in online social networks (OSNs), where authorization is typically made by tracking the existence of a U2U relationship of particular type and/or depth between the accessing user and the resource owner. However, today´s OSN applications allow various user activities that cannot be controlled by using U2U relationships alone. In this paper, we develop a relationship-based access control model for OSNs that incorporates not only U2U relationships but also user-to-resource (U2R) and resource-to-resource (R2R) relationships. Furthermore, while most access control proposals for OSNs only focus on controlling users´ normal usage activities, our model also captures controls on users´ administrative activities. Authorization policies are defined in terms of patterns of relationship paths on social graph and the hop count limits of these path. The proposed policy specification language features hop count skipping of resource-related relationships, allowing more flexibility and expressive power. We also provide simple specifications of conflict resolution policies to resolve possible conflicts among authorization policies.
  • Keywords
    authorisation; graph theory; social networking (online); specification languages; OSN applications; R2R relationships; U2U relationship-based access control; access control proposals; authorization policy; conflict resolution policy; hop count limits; hop count skipping; normal usage activity; online social networks; policy specification language; relationship paths; resource-related relationships; resource-to-resource relationships; social graph; user-to-user relationship-based access control; user-to-user relationships; users administrative activity; Authorization; Blogs; Facebook; Taxonomy; Access Control; Security; Social Networks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Privacy, Security, Risk and Trust (PASSAT), 2012 International Conference on and 2012 International Confernece on Social Computing (SocialCom)
  • Conference_Location
    Amsterdam
  • Print_ISBN
    978-1-4673-5638-1
  • Type

    conf

  • DOI
    10.1109/SocialCom-PASSAT.2012.57
  • Filename
    6406322