An access control framework for hybrid policies

  • Authors:
  • Salim Khamadja;Kamel Adi;Luigi Logrippo

  • Affiliations:
  • Ecole Militaire Polytechnique, Alger, Algérie;Université du Québec en Outaouais, Gatineau, QC, Canada;Université du Québec en Outaouais, Gatineau, QC, Canada

  • Venue:
  • Proceedings of the 6th International Conference on Security of Information and Networks
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

Several formal access control models are known in the literature, such as DAC, MAC, RBAC, etc. However, these models cannot meet new security requirements required by flexible and dynamic environments which necessitate a combination of elements of these models, in order to properly express varied data protection needs. In this paper, we present a new method for the specification of access control systems. The method makes it possible to design an access control system specific to the high level policy of an organization. The method is based on a generic UML meta-model of access control called CatBAC (Category Based Access Control), together with a refinement process for the extraction of security requirements from high level policies. Based on the category concept, the CatBAC meta-model allows specifying hybrid policies of access control.