Security Analysis of ABAC under an Administrative Model.


Journal

IET information security
ISSN: 1751-8717
Titre abrégé: IET Inf Secur
Pays: England
ID NLM: 101738715

Informations de publication

Date de publication:
Mar 2019
Historique:
entrez: 20 6 2019
pubmed: 20 6 2019
medline: 20 6 2019
Statut: ppublish

Résumé

In the present day computing environment, where access control decisions are often dependent on contextual information like the location of the requesting user and the time of access request, Attribute Based Access Control (ABAC) has emerged as a suitable choice for expressing security policies. In an ABAC system, access decisions depend on the set of attribute values associated with the subjects, resources and the environment in which an access request is made. In such systems, the task of managing the set of attributes associated with the entities as well as that of analyzing and understanding the security implications of each attribute assignment is of paramount importance. In this paper, we first introduce a comprehensive attribute based administrative model, named as AMABAC (Administrative Model for ABAC), for ABAC systems and then suggest a methodology for analyzing the security properties of ABAC in the presence of the administrative model. For performing analysis, we use

Identifiants

pubmed: 31214270
doi: 10.1049/iet-ifs.2018.5010
pmc: PMC6581459
mid: NIHMS998815
doi:

Types de publication

Journal Article

Langues

eng

Pagination

96-103

Subventions

Organisme : NIGMS NIH HHS
ID : R01 GM118574
Pays : United States

Auteurs

Sadhana Jha (S)

Advanced Technology Development Center, Indian Institute of Technology, Kharagpur, India.

Shamik Sural (S)

Department of Computer Science & Engineering, Indian Institute of Technology, Kharagpur, India.

Vijayalakshmi Atluri (V)

Management Science & Information Systems Department, Rutgers University, USA.

Jaideep Vaidysa (J)

Management Science & Information Systems Department, Rutgers University, USA.

Classifications MeSH