Title :
A research challenge in modeling access control policies: Modeling recommendations
Author :
El Kalam, Anas Abou
Author_Institution :
IRIT - INPT / ENSEEIHT, Univ. de Toulouse, Toulouse
Abstract :
Security Policies should be well-defined in any serious security study and should capture all the requirements of the targeted system. However, while current and emergent applications become more and more complex, most of the existing security policies and models only consider a yes/no response to the access requests. Consequently, modeling, formalizing and implementing permissions, obligations and prohibitions do not cover the richness of all the possible scenarios. In fact, many applications have access rules with the recommendation access modality. In this paper we focus on the problem of security policies formalization. The aim is to provide a generic domain- independent approach. In order to achieve these goals, we have chosen a logic-based approach that enhances the Deontic logic (the logic of permissions, obligations and prohibitions) with the recommendation and inadvisable access modalities. We thus present a new logical framework including a Recommendation Specification Language (RSL) as well as the necessary axiomatic to derive rules and to reason (e.g., query, verify) on the security policy. Our logical framework can thus be used by security administrators to automatically derive consequences of their policies.
Keywords :
authorisation; formal logic; specification languages; access control policy modeling; deontic logic; generic domain-independent approach; logic-based approach; recommendation access modality; recommendation specification language; security policy formalization; Access control; Current control; Data security; Guidelines; Information security; Legislation; Logic; Medical services; Permission; Specification languages; Deontic logic; Information systems security; access control models; security policies;
Conference_Titel :
Research Challenges in Information Science, 2008. RCIS 2008. Second International Conference on
Conference_Location :
Marrakech
Print_ISBN :
978-1-4244-1677-6
Electronic_ISBN :
978-1-4244-2273-9
DOI :
10.1109/RCIS.2008.4632115