作者
Petar Tsankov, Srdjan Marinovic, Mohammad Torabi Dashti, David Basin
发表日期
2014/1/1
研讨会论文
Principles of Security and Trust
页码范围
245-264
出版商
Springer Berlin Heidelberg
简介
Formal foundations for access control policies with both authority delegation and policy composition operators are partial and limited. Correctness guarantees cannot therefore be formally stated and verified for decentralized composite access control systems, such as those based on XACML 3. To address this problem we develop a formal policy language BelLog that can express both delegation and composition operators. We illustrate, through examples, how BelLog can be used to specify practical policies. Moreover, we present an analysis framework for reasoning about BelLog policies and we give decidability and complexity results for policy entailment and policy containment in BelLog.
引用总数
20142015201620172018201920202021202221456511
学术搜索中的文章
P Tsankov, S Marinovic, MT Dashti, D Basin - Principles of Security and Trust: Third International …, 2014