Ontology-based Evaluation of ABAC Policies for Inter-Organizational Resource Sharing

Tushar Gupta,Shamik Sural

PROCEEDINGS OF THE 9TH ACM INTERNATIONAL WORKSHOP ON SECURITY AND PRIVACY ANALYTICS, IWSPA 2023(2023)

引用 0|浏览8
暂无评分
摘要
Attribute-based Access Control (ABAC), as the name suggests, determines whether an access request be granted based on the attributes or characteristics of the requesting user, those of the requested resource, and the environmental condition in which the request is generated. An important advantage of such an identity-agnostic model is that access control can be imposed even on users from other organizations if they are able to prove their attributes to the reference monitor of the organization whose resources are being accessed. It would, however, require a mechanism for mapping the attributes and their values among these organizations. We propose an ontology based method for addressing this requirement. Besides meeting the needs of collaborative accesses, we show how such an approach can be made to naturally support hierarchical ABAC policies as well as controlled relaxation during policy enforcement.
更多
查看译文
关键词
Attribute-based Access Control,Resource Sharing,Ontology,Attribute Hierarchy,Policy Relaxation,Digital Signature
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要