Inicio  /  Future Internet  /  Vol: 12 Par: 10 (2020)  /  Artículo
ARTÍCULO
TITULO

Policy-Engineering Optimization with Visual Representation and Separation-of-Duty Constraints in Attribute-Based Access Control

Wei Sun    
Hui Su and Huacheng Xie    

Resumen

Recently, attribute-based access control (ABAC) has received increasingly more attention and has emerged as the desired access control mechanism for many organizations because of its flexibility and scalability for authorization management, as well as its security policies, such as separation-of-duty constraints and mutually exclusive constraints. Policy-engineering technology is an effective approach for the construction of ABAC systems. However, most conventional methods lack interpretability, and their constructing processes are complex. Furthermore, they do not consider the separation-of-duty constraints. To address these issues in ABAC, this paper proposes a novel method called policy engineering optimization with visual representation and separation of duty constraints (PEO_VR&SOD). First, to enhance interpretability while mining a minimal set of rules, we use the visual technique with Hamming distance to reduce the policy mining scale and present a policy mining algorithm. Second, to verify whether the separation of duty constraints can be satisfied in a constructed policy engineering system, we use the method of SAT-based model counting to reduce the constraints and construct mutually exclusive constraints to implicitly enforce the given separation of duty constraints. The experiments demonstrate the efficiency and effectiveness of the proposed method and show encouraging results.

 Artículos similares

       
 
Ying Zhou, Amelia Clarke and Stephanie Cairns    
In recent years, sustainable community development has gained traction for addressing local environmental, social, and economic issues. Cities worldwide are committed to implementing sustainable community plans (SCPs) in their efforts to achieve sustaina... ver más
Revista: Urban Science

 
Boer Cui, Genevieve Boisjoly, Bernardo Serra, Ahmed El-Geneidy     Pág. 1?15
In the context of increasing urbanization and income inequality, transport professionals in the Global South need to be prepared to effectively plan for the needs of various groups within the population, particularly for those regarding health and well-b... ver más

 
Hao Zhou, Yong Chen and Ruoying Tian    
Land-use conflict (LUC) is a major problem of land management in the context of rapid urbanization. Conflict identification plays an important role in the development and protection of land space. Considering the possibility of, exposure to, and negative... ver más

 
Mingli Song and Guangshe Jia    
The construction and operation of air transport systems (ATS) needs huge investment, so its performance is of wide concern. The influences of social and economic factors in different regions must be considered when evaluating ATS performance. In this pap... ver más

 
David P. Anderson    
Volunteer computing uses millions of consumer computing devices (desktop and laptop computers, tablets, phones, appliances, and cars) to do high-throughput scientific computing. It can provide Exa-scale capacity, and it is a scalable and sustainable alte... ver más
Revista: Future Internet