A Formal Perspective on Relation Based Access Control ?

Alessandro Artale,Bruno Crispo,Fausto Giunchiglia,Rui Zhang
2009-01-01
Abstract:Relation Based Access Control (RelBAC ) is an access con- trol model designed for the new scenarios of access control on Web 2.0. Under this model, we discuss in this paper how to formalize typical access control policies with Description Logics. Important security properties, i.e., Separation of Duties (SoD) and Chinese Wall constraints are studied and formally represented in RelBAC with the expressive DLALCQIBO. To meet the needs of automated tools for administrators, RelBAC can formalize and answer queries about access control requests and admin- istrative checks resorting to the reasoning services of the underlying De- scription Logic.
What problem does this paper attempt to address?