DocumentCode
579301
Title
CatBAC: A generic framework for designing and validating hybrid access control models
Author
Stepien, Bernard ; Khambhammettu, Hemanth ; Adi, Kamel ; Logrippo, Luigi
Author_Institution
Dept. of Comput. Sci. & Eng., Univ. of Ottawa, Ottawa, ON, Canada
fYear
2012
fDate
10-15 June 2012
Firstpage
6721
Lastpage
6726
Abstract
Many access control models have been proposed in the literature, and they have been extensively studied under the acronyms of DAC, MAC, RBAC, ABAC, etc. Each of these models has been studied in isolation, but some real-life situations need elements of several of them, in order to properly express data protection needs of complex organizations. A formal framework is presented, that allows not only to combine elements of these models, but also to generalize them in new ways. This framework includes elements of a lifecycle methodology, which starts with a UML-based formalism, called UACML, that expresses semantic elements (classes and their relationships) needed for general access control systems. It continues with the representation of UACML diagrams in our language CatBAC. The latter is a compact textual representation of UACML that makes it possible to express realistic policy systems involving many entities and many constraints. CatBAC is based on Prolog, and this makes it possible to implement analysis and verification tools.
Keywords
PROLOG; Unified Modeling Language; authorisation; formal verification; programming language semantics; ABAC; CatBAC language; DAC; MAC; PROLOG; RBAC; UACML compact textual representation; UACML diagrams; UML-based formalism; data protection; formal verification framework; general access control systems; hybrid access control models; lifecycle methodology; realistic policy systems; semantic elements; Abstracts; Access control; Computational modeling; Electronic mail; Engines; Visualization; Access control models and languages; Prolog; Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications (ICC), 2012 IEEE International Conference on
Conference_Location
Ottawa, ON
ISSN
1550-3607
Print_ISBN
978-1-4577-2052-9
Electronic_ISBN
1550-3607
Type
conf
DOI
10.1109/ICC.2012.6364961
Filename
6364961
Link To Document