• DocumentCode
    33673
  • Title

    Abductive Analysis of Administrative Policies in Rule-Based Access Control

  • Author

    Gupta, Puneet ; Stoller, Scott D. ; Zhongyuan Xu

  • Author_Institution
    Google, Inc., Mountain View, CA, USA
  • Volume
    11
  • Issue
    5
  • fYear
    2014
  • fDate
    Sept.-Oct. 2014
  • Firstpage
    412
  • Lastpage
    424
  • Abstract
    In large organizations, access control policies are managed by multiple users (administrators). An administrative policy specifies how each user in an enterprise may change the policy. Fully understanding the consequences of an administrative policy in an enterprise system can be difficult, because of the scale and complexity of the access control policy and the administrative policy, and because sequences of changes by different users may interact in unexpected ways. Administrative policy analysis helps by answering questions such as user-permission reachability, which asks whether specified users can together change the policy in a way that achieves a specified goal, namely, granting a specified permission to a specified user. This paper presents a rule-based access control policy language, a rule-based administrative policy model that controls addition and removal of facts and rules, and an abductive analysis algorithm for user-permission reachability. Abductive analysis means that the algorithm can analyze policy rules even if the facts initially in the policy (e.g., information about users) are unavailable. The algorithm does this by computing minimal sets of facts that, if present in the initial policy, imply reachability of the goal.
  • Keywords
    DP management; authorisation; abductive analysis algorithm; administrative policy; enterprise system; rule-based access control; user-permission reachability; Access control; Algorithm design and analysis; Grammar; Hospitals; Organizations; Semantics; Security policy; attribute-based access control; policy administration; policy verification; rule-based policy;
  • fLanguage
    English
  • Journal_Title
    Dependable and Secure Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1545-5971
  • Type

    jour

  • DOI
    10.1109/TDSC.2013.42
  • Filename
    6616529