Reasoning about the state change of authorization policies

Yun Bai, Edward Caprin, Yan Zhang

    Research output: Chapter in Book / Conference PaperConference Paperpeer-review

    1 Citation (Scopus)

    Abstract

    Reasoning about authorization policies has been a prominent issue in information security research. In a complex information sharing and exchange environment, a user's request may initiate a sequence of executions of authorization commands in order to decide whether such request should be granted or denied. Becker and Nanz's logic of State- Modifying Policies (SMP) is a formal system addressing such problem in access control. In this paper, we provide a declarative semantics for SMP through a translation from SMP to Answer Set Programming (ASP). We show that our translation is sound and complete for bounded SMP reasoning. With this translation, we are able not only to directly compute users' authorization query answers, but also to specifically extract information of how users' authorization states change in relation to the underlying query answering. In this way, we eventually avoid SMP's tedious proof system and significantly simply the SMP reasoning process. Furthermore, we argue that the proposed ASP translation of SMP also provides a flexibility to enhance SMP's capacity for accommodating more complex authorization reasoning problems that the current SMP lacks.
    Original languageEnglish
    Title of host publicationCurrent Approaches in Applied Artificial Intelligence, 28th International Conference on Industrial, Engineering and Other Applications of Applied Intelligent Systems, IEA/AIE 2015, Seoul, South Korea, June 10-12, 2015: Proceedings
    PublisherSpringer
    Pages109-119
    Number of pages11
    ISBN (Print)9783319190655
    DOIs
    Publication statusPublished - 2015
    EventInternational Conference on Industrial & Engineering Applications of Artificial Intelligence & Expert Systems -
    Duration: 10 Jun 2015 → …

    Publication series

    Name
    ISSN (Print)0302-9743

    Conference

    ConferenceInternational Conference on Industrial & Engineering Applications of Artificial Intelligence & Expert Systems
    Period10/06/15 → …

    Keywords

    • access control
    • intelligent agents (computer software)
    • knowledge representation (information theory)
    • logic programming
    • semantics

    Fingerprint

    Dive into the research topics of 'Reasoning about the state change of authorization policies'. Together they form a unique fingerprint.

    Cite this