Abstract
Tag-Based Authorization (TBA) is a hybrid access control model that combines the ease of use of extensional access control models with the expressivity of logic-based formalisms. The main limitation of TBA is that it lacks support for policy administration. More precisely, it does not allow policy-writers to specify administrative policies that constrain the tags that users can assign, and to verify the compliance of assigned tags with these policies. In this paper we introduce TBA2 (Tag-Based Authorization & Administration), an extension of TBA that enables policy administration in distributed systems. We show that TBA2 is more expressive than TBA and than two reference administrative models proposed in the literature, namely HRU and ARBAC97.
Original language | Undefined |
---|---|
Title of host publication | 5th International Symposium on Foundations and Practice of Security, FPS 2012 |
Place of Publication | Berlin |
Publisher | Springer |
Pages | 162-179 |
Number of pages | 18 |
ISBN (Print) | 978-3-642-37119-6 |
DOIs | |
Publication status | Published - 2013 |
Event | 5th International Symposium on Foundations and Practice of Security 2012 - Montreal, Canada Duration: 25 Oct 2012 → 26 Oct 2012 Conference number: 5 http://conferences.telecom-bretagne.eu/fps2012/ |
Publication series
Name | Lecture Notes in Computer Science |
---|---|
Publisher | Springer Verlag |
Volume | 7743 |
ISSN (Print) | 0302-9743 |
ISSN (Electronic) | 1611-3349 |
Conference
Conference | 5th International Symposium on Foundations and Practice of Security 2012 |
---|---|
Abbreviated title | FPS 2012 |
Country/Territory | Canada |
City | Montreal |
Period | 25/10/12 → 26/10/12 |
Internet address |
Keywords
- EWI-23344
- SCS-Cybersecurity
- policy administration
- IR-86128
- Access Control
- METIS-297634
- auditing