Dynamic Information Management and Exchange for Command and Control Applications, Modelling and Enforcing Category-Based Access Control via Term Rewriting
Abstract
The main goal of this project was to develop a new model of access control to facilitate the specification of policies in highly dynamic scenarios. The requirement was to have a mathematically well defined model so that properties of policies can be proven, and so that verifiably correct systems can be developed. We have achieved this general goal: we have developed an expressive category-based metamodel of access control, which has a rewrite-based semantics allowing us to prove correctness properties of policies. Previously defined access control models are instances of our metamodel and in addition the metamodel encompasses distributed models, as well as federative policies (where a global access control policy governing the federation is defined as a composition of local policies specified by individual members of the federation).
Document Details
- Document Type
- Technical Report
- Publication Date
- Mar 01, 2015
- Accession Number
- ADA622827
Entities
People
- Anatoli Degtyarev
- Maribel Fernández
Organizations
- King's College London