DocumentCode :
2953045
Title :
Authorisation and Conflict Resolution for Hierarchical Domains
Author :
Russello, Giovanni ; Dong, Changyu ; Dulay, Naranker
Author_Institution :
Imperial Coll. London, London
fYear :
2007
fDate :
13-15 June 2007
Firstpage :
201
Lastpage :
210
Abstract :
In this paper we generalise the authorisation policy model supported by the Ponder policy language for hierarchically organised domains of managed objects to support subject-based policies and return policies. We describe the authorisation conflicts that can occur and present a strategy to automatically resolve them. In our model each action has four endpoints: the subject call, the subject return, the target call and the target return. Each endpoint can have associated policies which are used to define constraints on which subjects are permitted to call which targets, and what is permitted to be transferred between subjects and targets. Subject-based policies aim to protect the subject from untrusted targets, while target-based policies aim to protect the target from unauthorised subjects. Subject-based policies are defined for and enforced by the subject´s PEP, while target-based policies are defined for and enforced by the target´s PEP. Although subject-based and target-based policies are separated, they are uniformly specified in our framework.
Keywords :
authorisation; programming languages; Ponder policy language; authorisation; conflict resolution; hierarchical domains; subject-based policies; target-based policies; Access control; Authorization; Automation; Computer crime; Costs; Information security; Logic; Monitoring; Protection; Technology management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Policies for Distributed Systems and Networks, 2007. POLICY '07. Eighth IEEE International Workshop on
Conference_Location :
Bologna
Print_ISBN :
0-7695-2767-1
Type :
conf
DOI :
10.1109/POLICY.2007.8
Filename :
4262589
Link To Document :
بازگشت