A System to Specify and Manage Multipolicy Access Control Models

  • Authors:
  • E. Bertino;B. Catania;E. Ferrari;P. Perlasca

  • Affiliations:
  • -;-;-;-

  • Venue:
  • POLICY '02 Proceedings of the 3rd International Workshop on Policies for Distributed Systems and Networks (POLICY'02)
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper describes the architecture and the core specificationlanguage of an extensible access control system,called MACS - Multipolicy Access Control System.Severalaccess control models are supported by the proposedsystem, including the mandatory model, a flexible discretionarymodel, and RBAC. In addition, by using the corespecification language, users can define their own accesscontrol models. The language is complemented by a numberof tools supporting users in the tasks of model specificationand analysis, and authorization management. Theproposed system is a multipolicy system in that it allows oneto apply different policies to different partitions of the set ofobjects to be protected. Therefore, different access controlpolicies can co-exist, thus enhancing the flexibility of thesystem.