PolicyMorph: Interactive policy transformations for a logical attribute-based access control framework

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Constraint systems provide techniques for automatically analyzing the conformance of low-level access control policies to high-level business rules formalized as logical constraints. However, there are likely to be priorities for solutions that are not easy to encode formally, so administrator input is often important. This paper introduces PolicyMorph, a constraint system that supports interactive development and maintenance of access control policies that respect both formalized and un-formalized business rules and priorities. We provide a mathematical description of the system and an architecture for implementing it. We constructed a prototype that is validated using a case study in which constraints are imposed on a building automation system that controls door locks. PolicyMorph advances the state-of-the-art in constraint systems by suggesting predictable policy model modifications that will resolve specific constraint violations and then allowing policy administrators to select the appropriate modifications using knowledge that is not formally encoded in the constraint system.

Original languageEnglish (US)
Title of host publicationSACMAT'07
Subtitle of host publicationProceedings of the 12th ACM Symposium on Access Control Models and Technologies
PublisherAssociation for Computing Machinery
Pages205-214
Number of pages10
ISBN (Print)1595937455, 9781595937452
DOIs
StatePublished - 2007
EventSACMAT'07: 12th ACM Symposium on Access Control Models and Technologies - Sophia Antipolis, France
Duration: Jun 20 2007Jun 22 2007

Publication series

NameProceedings of ACM Symposium on Access Control Models and Technologies, SACMAT

Other

OtherSACMAT'07: 12th ACM Symposium on Access Control Models and Technologies
Country/TerritoryFrance
CitySophia Antipolis
Period6/20/076/22/07

Keywords

  • Attribute based access control
  • Constraints
  • Policy administration
  • Separation of duty

ASJC Scopus subject areas

  • General Computer Science

Fingerprint

Dive into the research topics of 'PolicyMorph: Interactive policy transformations for a logical attribute-based access control framework'. Together they form a unique fingerprint.

Cite this