A first-order logic based approach for authorization with the treatment ofpolicy inconsistency

Hongyan Yao,Mingchu Li
2010-01-01
Abstract:Logic-based anthorization has been arisen in recent years and to reasonpolicy for getting authorization decision is of central position in it. Howeverthere may have a policy inconsistency problem dnring the process of policycombination if policy contains negative rules. This problem will make policydeduction time-consnming and authorization decision intractable. To solve thisproblem, the paper presents a logic-based approach for reasoning policy to getanthorization decision even though the policy is inconsistent. The approachadopts the operation of replacement and combination to adjust policy consistentat first, and then follows the result to reason policy for final decision. Thealgorithm for final decision runs in polynomial-time Omicron;(n2T/2).It is almost the same with Ο(Mn2T) in PolicyMaker TrustManagement System, but in which negative rules are excluded. ICIC International © 2010.
What problem does this paper attempt to address?