Provisional Authorizations

نویسندگان

  • Sushil Jajodia
  • Michiharu Kudo
  • V. S. Subrahmanian
چکیده

Past generations of access control systems, when faced with an access request, have issued a “yes” (resp. “no”) answer to the access request resulting in access being granted (resp. denied). In this paper, we argue that for the world’s rapidly proliferating business to business (B2B) applications and auctions, “yes/no” responses are just not enough. We propose the notion of a “provisional authorization” which intuitively says “You may perform the desired access provided you cause condition C to be satisfied.” For instance, a user accessing an online brokerage may receive some information if he fills out his name/address, but not otherwise. While a variety of such provisional authorization mechanisms exist on the web, they are all hardcoded on an application by application basis. We show that given (almost) any logic L, we may define a provisional authorization specification language pASLL. pASLL is based on the declarative, polynomially evaluable authorization specification language ASL proposed by Jajodia et al. We define programs in pASLL, and specify how given any access request, we must find a “weakest” precondition under which the access can be granted (in the worst case, if this weakest precondition is “false” this amounts to a denial). We develop a model theoretic semantics for pASLL and show how it can be applied to online sealed-bid auction servers and online contracting.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Recycling Authorizations: Toward Secondary and Approximate Authorizations Model (SAAM)

In large and complex enterprises, obtaining authorizations could be communicationally and/or computationally expensive, and, due to infrastructure failures, some times even impossible. This paper establishes the concept of recycling previously made authorizations for serving new authorization requests. It introduces secondary and approximate authorizations model (SAAM) with the semantics of mat...

متن کامل

A Temporal Access Control Mechanism for Database Systems

This paper presents a discretionary access control model in which authorizations contain temporal intervals of validity. An authorization is automatically revoked when the associated temporal interval expires. The proposed model provides rules for the automatic derivation of new authorizations from those explicitly speci ed. Both positive and negative authorizations are supported. A formal de n...

متن کامل

Data Handling: Dependencies between Authorizations and Obligations

Authorizations and obligations are keystones of data handling. On one hand there are ambiguous links between authorization and obligations. On the other hand a clear separation between both concepts is necessary to improve readability and to avoid inconsistencies. This position paper focuses on authorizations necessary to enforce obligations. Such authorizations are necessary to prevents overdi...

متن کامل

Supporting Periodic Authorizations and Temporal Reasoning in Database Access Control

Several formal models for database access control have been proposed. However, little attention has been paid to temporal issues like authorizations with limited validity or obtained by deductive reasoning with temporal constraints. We present an access control model in which authorizations contain periodic temporal intervals of validity. An authorization is automatically granted in the time in...

متن کامل

Coups, Corporations, and Classified Information∗ Arindrajit Dube

We estimate the impact of coups and top-secret coup authorizations on asset prices of partially nationalized multinational companies that stood to benefit from U.S.-backed coups. Stock returns of highly exposed firms reacted to coup authorizations classified as top-secret. The average cumulative abnormal return to a coup authorization was 9% over 4 days for a fully nationalized company, rising ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2001