pith. sign in

arxiv: 1405.1584 · v1 · pith:DOGTYZ3Jnew · submitted 2014-05-07 · 💻 cs.LO · cs.CR

Modelling Delegation and Revocation Schemes in IDP

classification 💻 cs.LO cs.CR
keywords revocationschemesaccesschainscontroldelegationdifferentownership-based
0
0 comments X
read the original abstract

In ownership-based access control frameworks with the possibility of delegating permissions and administrative rights, chains of delegated accesses will form. There are different ways to treat these delegation chains when revoking rights, which give rise to different revocation schemes. In this paper, we show how IDP - a knowledge base system that integrates technology from ASP, SAT and CP - can be used to efficiently implement executable revocation schemes for an ownership-based access control system based on a declarative specification of their properties.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.