An Approach for Resolving Inconsistency Conflicts in Access Control Policies

LI Rui-Xuan,LU Jian-Feng,LI Tian-Yi,GU Xi-Wu,TANG Zhuo
DOI: https://doi.org/10.3724/sp.j.1016.2013.01210
2013-01-01
Chinese Journal of Computers
Abstract:Inconsistency conflicts may arise between static separation-of-duty and availability policies due to their opposite focuses.This paper provides a priority-based approach to resolve policy inconsistency conflicts.Considering the facts of the policy strictness and its influence on the whole policy set,we propose a method to calculate the policy priority.The concepts of self-satisfied frequency and weighted conflict area are introduced to denote the policy strictness and its influence on the whole policy set respectively.Based on these two concepts,two algorithms for inconsistency resolution are presented according to different objectives of the policies: minimum cost algorithm and lexicographical inference algorithm.The experimental results show that the proposed priority-based conflict resolution approach scales reasonably well when the number of static separation-of-duty and availability policies is not very large.
What problem does this paper attempt to address?