Refinement for administrative policies

  • Authors:
  • M. A. C. Dekker;S. Etalle

  • Affiliations:
  • Security group, TNO ICT, The Netherlands and Distributed and Embedded Systems group, University of Twente, The Netherlands;Distributed and Embedded Systems group, University of Twente, The Netherlands

  • Venue:
  • SDM'07 Proceedings of the 4th VLDB conference on Secure data management
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Flexibility of management is an important requisite for access control systems as it allows users to adapt the access control system in accordance with practical requirements. This paper builds on earlier work where we defined administrative policies for a general class of RBAC models. We present a formal definition of administrative refinement and we show that there is an ordering for administrative privileges which yields administrative refinements of policies. We argue (by giving an example) that this privilege ordering can be very useful in practice, and we prove that the privilege ordering is tractable.