1
IRUS Total
Downloads
  Altmetric

Policy-based access control from numerical evidence

File Description SizeFormat 
DTR13-6.pdfPublished version420.72 kBAdobe PDFView/Open
Title: Policy-based access control from numerical evidence
Authors: Crampton, J
Huth, M
Morisset, C
Item Type: Report
Abstract: Increasingly, access to resources needs to be regulated or informed by considerations such as risk, cost, and reputation. We therefore propose a framework for policy languages, based on semi-rings, that aggregate quantitative evidence to support decision-making in access control systems. As aggregation operators \addition", \worst case", and \best case" over non- negative reals are both relevant in practice and amenable to analysis, we study an instance, Peal, of our framework in that setting. Peal is a stand-alone policy language but can also be integrated with existing policy languages. Peal policies can be synthesized into logical formulae that no longer make reference to quantities but capture all policy behavior. Satis ability checking of such formulae can be used to validate and analyze policies in this new evidence-based approach. We discuss a number of applications, including vacuity, redundancy, change-impact and safety analysis. The synthesis algorithm requires a form of subset enumeration, for which we develop bespoke algorithms and demonstrate experimentally that our algorithms work better than generic state exploration methods. We also sketch how our approach extends from non-negative reals to other semi-rings and even to rings such as the real numbers.
Issue Date: 1-Jan-2013
URI: http://hdl.handle.net/10044/1/95058
DOI: 10.25561/95058
Publisher: Department of Computing, Imperial College London
Start Page: 1
End Page: 21
Journal / Book Title: Departmental Technical Report: 13/6
Copyright Statement: © 2013 The Author(s). This report is available open access under a CC-BY-NC-ND (https://creativecommons.org/licenses/by-nc-nd/4.0/)
Publication Status: Published
Article Number: 13/6
Appears in Collections:Computing
Computing Technical Reports
Faculty of Engineering



This item is licensed under a Creative Commons License Creative Commons