Skip to main navigation Skip to search Skip to main content

Admin-CBAC: An Administration Model for Category-Based Access Control

Research output: Chapter in Book/Report/Conference proceedingConference paperpeer-review

8 Citations (Scopus)

Abstract

We present Admin-CBAC, an administrative model for Category- Based Access Control (CBAC). Since most of the access control models in use nowadays are instances of CBAC, in particular the popular RBAC and ABAC models, from Admin-CBAC we derive administrative models for RBAC and ABAC too. We define Admin- CBAC using Barker's metamodel, and use its axiomatic semantics to derive properties of administrative policies. Using an abstract operational semantics for administrative actions, we show how properties (such as safety, liveness and effectiveness of policies) and constraints (such as separation of duties) can be checked, and discuss the impact of policy changes. Although the most interesting properties of policies are generally undecidable in dynamic access control models, we identify particular cases where reachability based properties are decidable and can be checked using our operational semantics, generalising previous results for RBAC and ABACalpha.

Original languageEnglish
Title of host publicationCODASPY 2020 - Proceedings of the 10th ACM Conference on Data and Application Security and Privacy
PublisherAssociation for Computing Machinery, Inc
Pages73-84
Number of pages12
ISBN (Electronic)9781450371070
DOIs
Publication statusPublished - 16 Mar 2020
Event10th ACM Conference on Data and Application Security and Privacy, CODASPY 2020 - New Orleans, United States
Duration: 16 Mar 202018 Mar 2020

Publication series

NameCODASPY 2020 - Proceedings of the 10th ACM Conference on Data and Application Security and Privacy

Conference

Conference10th ACM Conference on Data and Application Security and Privacy, CODASPY 2020
Country/TerritoryUnited States
CityNew Orleans
Period16/03/202018/03/2020

Keywords

  • access control
  • attribute-based access control
  • category-based access control
  • policy administration
  • policy analysis
  • role-based access control

Fingerprint

Dive into the research topics of 'Admin-CBAC: An Administration Model for Category-Based Access Control'. Together they form a unique fingerprint.

Cite this