1
IRUS TotalDownloads
Altmetric
Policy-based access control from numerical evidence
File | Description | Size | Format | |
---|---|---|---|---|
DTR13-6.pdf | Published version | 420.72 kB | Adobe PDF | View/Open |
Title: | Policy-based access control from numerical evidence |
Authors: | Crampton, J Huth, M Morisset, C |
Item Type: | Report |
Abstract: | Increasingly, access to resources needs to be regulated or informed by considerations such as risk, cost, and reputation. We therefore propose a framework for policy languages, based on semi-rings, that aggregate quantitative evidence to support decision-making in access control systems. As aggregation operators \addition", \worst case", and \best case" over non- negative reals are both relevant in practice and amenable to analysis, we study an instance, Peal, of our framework in that setting. Peal is a stand-alone policy language but can also be integrated with existing policy languages. Peal policies can be synthesized into logical formulae that no longer make reference to quantities but capture all policy behavior. Satis ability checking of such formulae can be used to validate and analyze policies in this new evidence-based approach. We discuss a number of applications, including vacuity, redundancy, change-impact and safety analysis. The synthesis algorithm requires a form of subset enumeration, for which we develop bespoke algorithms and demonstrate experimentally that our algorithms work better than generic state exploration methods. We also sketch how our approach extends from non-negative reals to other semi-rings and even to rings such as the real numbers. |
Issue Date: | 1-Jan-2013 |
URI: | http://hdl.handle.net/10044/1/95058 |
DOI: | 10.25561/95058 |
Publisher: | Department of Computing, Imperial College London |
Start Page: | 1 |
End Page: | 21 |
Journal / Book Title: | Departmental Technical Report: 13/6 |
Copyright Statement: | © 2013 The Author(s). This report is available open access under a CC-BY-NC-ND (https://creativecommons.org/licenses/by-nc-nd/4.0/) |
Publication Status: | Published |
Article Number: | 13/6 |
Appears in Collections: | Computing Computing Technical Reports Faculty of Engineering |
This item is licensed under a Creative Commons License