Sciweavers

SACMAT
2006
ACM

The secondary and approximate authorization model and its application to Bell-LaPadula policies

14 years 6 months ago
The secondary and approximate authorization model and its application to Bell-LaPadula policies
We introduce the concept, model, and policy-specific algorithms for inferring new access control decisions from previous ones. Our secondary and approximate authorization model (SAAM) defines the notions of primary vs. secondary and precise vs. approximate authorizations. Approximate authorization responses are inferred from cached primary responses, and therefore provide an alternative source of access control decisions in the event that the authorization server is unavailable or slow. The ability to compute approximate authorizations improves the reliability and performance of access control sub-systems and ultimately the application systems themselves. The operation of a system that employs SAAM depends on the type of access control policy it implements. We propose and analyze algorithms for computing secondary authorizations in the case of policies based on the BellLaPadula model. In this context, we define a dominance graph, and describe its construction and usage for generati...
Jason Crampton, Wing Leung, Konstantin Beznosov
Added 14 Jun 2010
Updated 14 Jun 2010
Type Conference
Year 2006
Where SACMAT
Authors Jason Crampton, Wing Leung, Konstantin Beznosov
Comments (0)