TY - GEN
T1 - Reasoning on weighted delegatable authorizations
AU - Ruan, Chun
AU - Varadharajan, Vijay
PY - 2009
Y1 - 2009
N2 - This paper studies logic based methods for representing and evaluating complex access control policies needed by modern database applications. In our framework, authorization and delegation rules are specified in a Weighted Delegatable Authorization Program (WDAP) which is an extended logic program. We show how extended logic programs can be used to specify complex security policies which support weighted administrative privilege delegation, weighted positive and negative authorizations, and weighted authorization propagations. We also propose a conflict resolution method that enables flexible delegation control by considering priorities of authorization grantors and weights of authorizations. A number of rules are provided to achieve delegation depth control, conflict resolution, and authorization and delegation propagations.
AB - This paper studies logic based methods for representing and evaluating complex access control policies needed by modern database applications. In our framework, authorization and delegation rules are specified in a Weighted Delegatable Authorization Program (WDAP) which is an extended logic program. We show how extended logic programs can be used to specify complex security policies which support weighted administrative privilege delegation, weighted positive and negative authorizations, and weighted authorization propagations. We also propose a conflict resolution method that enables flexible delegation control by considering priorities of authorization grantors and weights of authorizations. A number of rules are provided to achieve delegation depth control, conflict resolution, and authorization and delegation propagations.
UR - http://www.scopus.com/inward/record.url?scp=70349321254&partnerID=8YFLogxK
U2 - 10.1007/978-3-642-03573-9_23
DO - 10.1007/978-3-642-03573-9_23
M3 - Conference proceeding contribution
AN - SCOPUS:70349321254
SN - 3642035728
SN - 9783642035722
VL - 5690 LNCS
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 279
EP - 286
BT - Database and Expert Systems Applications - 20th International Conference, DEXA 2009, Proceedings
CY - Berlin, Heidelberg
T2 - 20th International Conference on Database and Expert Systems Applications, DEXA 2009
Y2 - 31 August 2009 through 4 September 2009
ER -