On the relationship between finite domain ABAM and PreUCONA

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Scopus citations

Abstract

Several access control models that use attributes have been proposed, although none so far is regarded as a definitive characterization of attribute-based access control (ABAC). Among these a recently proposed model is the attribute-based access matrix (ABAM) model [14] that extends the HRU model [4] by introducing attributes. In this paper we consider the finite case of ABAM, where the number of attributes is finite and the permissible values (i.e., domain) for each attribute is finite. Henceforth, we understand ABAM to mean finite ABAM. A separately developed model with finite attribute domains is PreUCONA [10], which is a sub-model of the usage control UCON model [9]. This paper explores the relationship between the expressive power of these two finite attribute domain models. Since the safety problem for HRU is undecidable it follows safety is also undecidable for ABAM, while it is known to be decidable for PreUCONA [10]. Hence ABAM cannot be reduced to PreUCONA. We define a special case of ABAM called RL-ABAM2 and show that RL-ABAM2 and PreUCONA are equivalent in expressive power, but each has its own advantages. Finally, we propose a possible way to combine the advantages of these two models.

Original languageEnglish
Title of host publicationNetwork and System Security - 10th International Conference, NSS 2016, Proceedings
EditorsMoti Yung, Jiageng Chen, Chunhua Su, Vincenzo Piuri
PublisherSpringer Verlag
Pages333-346
Number of pages14
ISBN (Print)9783319462974
DOIs
StatePublished - 2016
Externally publishedYes
Event10th International Conference on Network and System Security, NSS 2016 - Taipei, Taiwan, Province of China
Duration: 28 Sep 201630 Sep 2016

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume9955 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference10th International Conference on Network and System Security, NSS 2016
Country/TerritoryTaiwan, Province of China
CityTaipei
Period28/09/1630/09/16

Fingerprint

Dive into the research topics of 'On the relationship between finite domain ABAM and PreUCONA'. Together they form a unique fingerprint.

Cite this