• DocumentCode
    2909355
  • Title

    Non-monotonocity in OrBAC through default and exception policy rules

  • Author

    Javadi, S.A. ; Amini, Milad ; Jalili, Rasool

  • fYear
    2012
  • fDate
    13-14 Sept. 2012
  • Firstpage
    87
  • Lastpage
    94
  • Abstract
    Context-awareness is an essential requirement of modern access control models. Organization-Based Access Control (OrBAC) model is a powerful context-aware access control model defined by first-order logic. However, due to the monotonicity nature of the first-order logic, OrBAC suffers from the incapability of making decision based on incomplete context information as well as the definition of default and exception policy rules. This paper proposes augmenting non-monotonicity features to OrBAC using MKNF+ logic, which is a combination of Description Logic (DL) and Answer Set Programming (ASP). Along with the use of DL to define ontology for main entities and context information in OrBAC; MKNF+ rules are used to define access control, default, and exception policy rules. The proposed model inherits the advantages of ontological representation of OrBAC entities and context information (such as interoperability among systems) as well as the ASP advantages in non-monotonic reasoning through closed-world principle and negation as failure. The expressive power of the model is also demonstrated through a case study.
  • Keywords
    authorisation; logic programming; nonmonotonic reasoning; ontologies (artificial intelligence); ubiquitous computing; MKNF+ logic; OrBAC; answer set programming; closed-world principle; context information; default rules; exception policy rules; first-order logic; nonmonotonic reasoning; nonmonotonocity feature; ontological representation; organization-based access control model; Access control; Cognition; Context; Context modeling; Knowledge based systems; Ontologies; Default Policy Rule; Exception Policy Rule; Non-monotonic Logic; Role-Based Access Control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Security and Cryptology (ISCISC), 2012 9th International ISC Conference on
  • Conference_Location
    Tabriz
  • Print_ISBN
    978-1-4673-2387-1
  • Type

    conf

  • DOI
    10.1109/ISCISC.2012.6408196
  • Filename
    6408196