LOCRMay 7, 2014

Modelling Delegation and Revocation Schemes in IDP

arXiv:1405.1584v1
Originality Synthesis-oriented
AI Analysis

This work addresses access control management for systems with delegation, but it is incremental as it applies existing methods to a specific domain.

The paper tackled the problem of implementing revocation schemes in ownership-based access control systems with delegation chains, and the result was an efficient executable implementation using the IDP knowledge base system based on declarative specifications.

In ownership-based access control frameworks with the possibility of delegating permissions and administrative rights, chains of delegated accesses will form. There are different ways to treat these delegation chains when revoking rights, which give rise to different revocation schemes. In this paper, we show how IDP - a knowledge base system that integrates technology from ASP, SAT and CP - can be used to efficiently implement executable revocation schemes for an ownership-based access control system based on a declarative specification of their properties.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes