Modelling Dynamic Access Control Policies for Web-Based Collaborative Systems - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2010

Modelling Dynamic Access Control Policies for Web-Based Collaborative Systems

Résumé

We present a modelling language, called X-Policy, for web-based collaborative systems with dynamic access control policies. The access to resources in these systems depends on the state of the system and its configuration. The X-Policy language models systems as a set of actions. These actions can model system operations which are executed by users. The X-Policy language allows us to specify execution permissions on each action using complex access conditions which can depend on data values, other permissions, and agent roles. We demonstrate that X-Policy is expressive enough to model collaborative conference management systems. We model the EasyChair conference management system and we reason about three security attacks on EasyChair.
Fichier principal
Vignette du fichier
_49.pdf (110.32 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01056680 , version 1 (20-08-2014)

Licence

Paternité

Identifiants

Citer

Hasan Qunoo, Mark Ryan. Modelling Dynamic Access Control Policies for Web-Based Collaborative Systems. 24th Annual IFIP WG 11.3 Working Conference on Data and Applications Security and Privacy (DBSEC), Jun 2010, Rome, Italy. pp.295-302, ⟨10.1007/978-3-642-13739-6_20⟩. ⟨hal-01056680⟩
60 Consultations
50 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More