Authors
Yehia Elrakaiby, Frédéric Cuppens, Nora Cuppens-Boulahia
Publication date
2010/2/15
Conference
2010 International Conference on Availability, Reliability and Security
Pages
70-78
Publisher
IEEE
Description
Pre-obligations denote actions which may be required before access is granted. The successful fulfillment of pre-obligations authorizes the requested access. Thus, preobligations induce interactions between the obligation and authorization policy states. This paper studies these interactionsby formalizing the evolution of the authorization and obligation states when pre-obligations are supported. The main advantage of the presented approach is that pre-obligations are given both declarative semantics based on predicate logic and operational semantics based on Event-Condition-Action (ECA) rules. Furthermore, the presented framework enables policy designers to easily choose to evaluate any pre-obligation either(1) statically (an access request is denied if the pre-obligation has not been fulfilled); (2) or dynamically (users are given the possibility to fulfill the pre-obligation after the access request and before …
Total citations
20102011201220135125
Scholar articles
Y Elrakaiby, F Cuppens, N Cuppens-Boulahia - … International Conference on Availability, Reliability and …, 2010