A Graphical Framework for the Category-Based Metamodel for Access Control and Obligations

10/31/2021
by   Sandra Alves, et al.
0

We design a graph-based framework for the visualisation and analysis of obligations in access control policies. We consider obligation policies in CBACO, the category-based access control model, which has been shown to subsume many of the most well known access control such as MAC, DAC, RBAC. CBACO is an extension of the CBAC metamodel that deals with obligations. We describe the implementation of the proposed model in PORGY, a strategy driven graph-rewriting tool, based on the theory of port-graphs. CBACO policies allow for dynamic behavior in the modelled systems, which is implemented using the strategy language of PORGY.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/21/2019

Graph Model Implementation of Attribute-Based Access Control Policies

Attribute-based access control (ABAC) promises a powerful way of formali...
research
05/31/2023

Modelling the Performance of High Capacity Access Networks for the Benefit of End-Users and Public Policies

This paper deals with the challenge of modeling the performance of plann...
research
06/22/2023

XACML Extension for Graphs: Flexible Authorization Policy Specification and Datastore-independent Enforcement

The increasing use of graph-structured data for business- and privacy-cr...
research
03/29/2023

Model Checking Access Control Policies: A Case Study using Google Cloud IAM

Authoring access control policies is challenging and prone to misconfigu...
research
12/01/2019

PACLP: a fine-grained partition-based access control policy language for provenance

Even though the idea of partitioning provenance graphs for access contro...
research
09/07/2018

On-line tracing of XACML-based policy coverage criteria

Currently, eXtensible Access Control Markup Language (XACML) has becomin...
research
05/15/2018

Towards Integrated Modelling of Dynamic Access Control with UML and Event-B

Role-Based Access Control (RBAC) is a popular authorization model used t...

Please sign up or login with your details

Forgot password? Click here to reset