Using Authority Certificates to Create Management Structures

  • Authors:
  • Babak Sadighi Firozabadi;Marek J. Sergot;Olav L. Bandmann

  • Affiliations:
  • -;-;-

  • Venue:
  • Revised Papers from the 9th International Workshop on Security Protocols
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

We address the issue of updating privileges in a dynamic environment by introducing authority certificates in a Privilege Management Infrastructure. These certificates can be used to create access-level permissions but also to delegate authority to other agents, thereby providing a mechanism for creating management structures and for changing these structures over time. We present a semantic framework for privileges and certificates and an associated calculus, encoded as a logic program, for reasoning about them. The framework distinguishes between the time a certificate is issued or revoked and the time for which the associated privilege is created. This enables certificates to have prospective and retrospective effects, and allows us to reason about privileges and their consequences in the past, present, and future. The calculus provides a verification procedure for determining, given a set of declaration and revocation certificates, whether a certain privilege holds.