Rewrite specifications of access control policies in distributed environments

  • Authors:
  • Clara Bertolissi;Maribel Fernández

  • Affiliations:
  • LIF, Université de Provence, Marseille, France;King's College London, Dept. of Computer Science, London, UK

  • Venue:
  • STM'10 Proceedings of the 6th international conference on Security and trust management
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

We define a metamodel for access control that takes into account the requirements of distributed environments, where resources and access control policies may be distributed across several sites. This distributed metamodel is an extension of the category-based metamodel proposed in previous work (from which standard centralised access control models such as MAC, DAC, RBAC, Bell-Lapadula, etc. can be derived). We use a declarative formalism in order to give an operational semantics to the distributed metamodel. We then show how various distributed access control models can be derived as instances of the distributed metamodel, including distributed models where each site implements a different kind of local access control model.