PolTree: A Data Structure for Making Efficient Access Decisions in ABAC.
ABAC
Access Decision
Attribute-Value Pair
Policy Tree
Journal
Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies
Titre abrégé: Proc ACM Symp Access Control Model Technol
Pays: United States
ID NLM: 101738720
Informations de publication
Date de publication:
Jun 2019
Jun 2019
Historique:
entrez:
27
7
2019
pubmed:
28
7
2019
medline:
28
7
2019
Statut:
ppublish
Résumé
In Attribute-Based Access Control (ABAC), a user is permitted or denied access to an object based on a set of rules (together called an ABAC Policy) specified in terms of the values of attributes of various types of entities, namely, user, object and environment. Efficient evaluation of these rules is therefore essential for ensuring decision making at on-line speed when an access request comes. Sequentially evaluating all the rules in a policy is inherently time consuming and does not scale with the size of the ABAC system or the frequency of access requests. This problem, which is quite pertinent for practical deployment of ABAC, surprisingly has not so far been addressed in the literature. In this paper, we introduce two variants of a tree data structure for representing ABAC policies, which we name as PolTree. In the binary version (B-PolTree), at each node, a decision is taken based on whether a particular attribute-value pair is satisfied or not. The n-ary version (N-PolTree), on the other hand, grows as many branches out of a given node as the total number of possible values for the attribute being checked at that node. An extensive experimental evaluation with diverse data sets shows the scalability and effectiveness of the proposed approach.
Identifiants
pubmed: 31346589
doi: 10.1145/3322431.3325102
pmc: PMC6658170
mid: NIHMS1036393
doi:
Types de publication
Journal Article
Langues
eng
Pagination
25-35Subventions
Organisme : NIGMS NIH HHS
ID : R01 GM118574
Pays : United States
Références
Shanghai Arch Psychiatry. 2015 Apr 25;27(2):130-5
pubmed: 26120265
Proc ACM Symp Access Control Model Technol. 2018 Jun;2018:213-215
pubmed: 30687851
IEEE Lett Comput Soc. 2018 Jul-Dec;1(2):25-29
pubmed: 30906923