An access control model supporting periodicity constraints and temporal reasoning

被引:123
作者
Bertino, E [1 ]
Bettini, C [1 ]
Ferrari, E [1 ]
Samarati, P [1 ]
机构
[1] Univ Milan, Dipartimento Sci Informaz, I-20135 Milan, Italy
来源
ACM TRANSACTIONS ON DATABASE SYSTEMS | 1998年 / 23卷 / 03期
关键词
access control; periodic authorization; temporal constraints; time management;
D O I
10.1145/293910.293151
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Access control models, such as the ones supported by commercial DBMSs, are not yet able to fully meet many application needs. An important requirement derives from the temporal dimension that permissions have in many real-world situations. Permissions are often limited in time or may hold only for specific periods of time. In this article, we present an access control model in which periodic temporal intervals are associated with authorizations. An authorization is automatically granted in the specified intervals and revoked when such intervals expire. Deductive temporal rules with periodicity and order constraints are provided to derive new authorizations based on the presence or absence of other authorizations in specific periods of time. We provide a solution to the problem of ensuring the uniqueness of the global set of valid authorizations derivable at each instant, and we propose an algorithm to compute this set. Moreover, we address issues related to the efficiency of access control by adopting a materialization approach. The resulting model provides a high degree of flexibility and supports the specification of several protection requirements that cannot be expressed in traditional access control models.
引用
收藏
页码:231 / 285
页数:55
相关论文
共 24 条
[1]   A CALCULUS FOR ACCESS-CONTROL IN DISTRIBUTED SYSTEMS [J].
ABADI, M ;
BURROWS, M ;
LAMPSON, B ;
PLOTKIN, G .
ACM TRANSACTIONS ON PROGRAMMING LANGUAGES AND SYSTEMS, 1993, 15 (04) :706-734
[2]  
[Anonymous], 1995, INTRO DATABASE SYSTE
[3]   A temporal access control mechanism for database systems [J].
Bertino, E ;
Bettini, C ;
Ferrari, E ;
Samarati, P .
IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 1996, 8 (01) :67-80
[4]   Decentralized administration for a temporal access control model [J].
Bertino, E ;
Bettini, C ;
Ferrari, E ;
Samarati, P .
INFORMATION SYSTEMS, 1997, 22 (04) :223-248
[5]  
BERTINO E, 1 ACM C COMP COMM SE, V130, P93
[6]  
BERTINO E, 1996, 22 VLDB BOMB IND, P472
[7]  
BERTINO E, 1996, POSTSIGMOD WORKSH MA, P34
[8]  
FALASCHI M, 1988, 5 INT C S LOG PROGR, P993
[9]  
FERRARI E, 1998, THESIS U MILANO
[10]  
FOUNDATION OS, 1993, OSF MOTIF PROGRAMMER