Artale, Alessandro and Crispo, Bruno and Giunchiglia, Fausto and Zhang, Rui (2009) A Formal Perspective on Relation Based Access Control. UNSPECIFIED. (Submitted)
Relation Based Access Control (RelBAC) is an access control model designed for the new scenarios of access control on Web 2.0. Under this model, we discuss in this paper how to formalize typical access control policies with Description Logics. Important security properties, i.e., Separation of Duties (SoD) and ChineseWall constraints are studied and formally represented in RelBAC with the expressive DL ALCQIBO. To meet the needs of automated tools for administrators, RelBAC can formalize and answer queries about access control requests and administrative checks resorting to the reasoning services of the underlying Description Logic.
Actions (login required)