Extended ReBAC Administrative models with cascading revocation and provenance support

Yuan Cheng, Khalid Bijon, Ravi Sandhu

Research output: Chapter in Book/Conference proceedingConference contributionpeer-review

9 Citations (Scopus)

Abstract

Relationship-based access control (ReBAC) has been widely studied and applied in the domain of online social networks, and has since been extended to domains beyond social. Us-ing ReBAC itself to manage ReBAC also becomes a natural research frontier, where we have two ReBAC administrative models proposed recently by Rizvi et al. [30] and Stoller [33]. In this paper, we extend these two ReBAC administrative models in order to apply ReBAC beyond online social net-works, particularly where edges can have dependencies with each other and authorization for certain administrative oper-Ations requires provenance information. Basically, our policy specifications adopt the concepts of enabling precondition and applicability preconditions from Rizvi et al. [30]. Then, we address several issues that need to be considered in order to properly execute operation effects, such as cascading re-vocation and integrity constraints on the relationship graph. With these extended features, we show that our administra-Tive models can provide the administration capability of the MT-RBAC model originally designed for multi-Tenant col-laborative cloud systems [34].

Original languageEnglish
Title of host publicationSACMAT 2016 - Proceedings of the 21st ACM Symposium on Access Control Models and Technologies
PublisherAssociation for Computing Machinery
Pages161-170
Number of pages10
ISBN (Electronic)9781450338028
DOIs
Publication statusPublished - 6 Jun 2016
Externally publishedYes
Event21st ACM Symposium on Access Control Models and Technologies, SACMAT 2016 - Shanghai, China
Duration: 6 Jun 20168 Jun 2016

Publication series

NameProceedings of ACM Symposium on Access Control Models and Technologies, SACMAT
Volume06-08-June-2016

Conference

Conference21st ACM Symposium on Access Control Models and Technologies, SACMAT 2016
Country/TerritoryChina
CityShanghai
Period6/06/168/06/16

Keywords

  • Access Control
  • Administrative Model
  • Relationship

ASJC Scopus subject areas

  • Software
  • Computer Networks and Communications
  • Safety, Risk, Reliability and Quality
  • Information Systems

Fingerprint

Dive into the research topics of 'Extended ReBAC Administrative models with cascading revocation and provenance support'. Together they form a unique fingerprint.

Cite this