A graphical definition of authorization schema in the DTAC model

  • Authors:
  • Jonathon E. Tidswell;John M. Potter

  • Affiliations:
  • Univ. of New South Wales, Sydney, Australia;Univ. of New South Wales, Sydney, Australia

  • Venue:
  • SACMAT '01 Proceedings of the sixth ACM symposium on Access control models and technologies
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

The specification of constraint languages for access control models has proven to be difficult but remains necessary for safety and for mandatory access control policies. While the authorisation relation $(Subject \times Object \rightarrow \pow Right)$ defines the authorised permissions an authorisation schema defines how the various concepts (such as subjects, users, roles, labels) are combined to form a complete access control model.Using examples drawn from common access control models in the literature we extend the authorisation schema of DTAC to define a general formalism for describing authorisation schema for any access control model.Based on our generic authorisation schema we define a new simpler constraint specification language which is as expressive as our previous graphical constraint languages and no more complex to verify.