pith. sign in

arxiv: cs/0601034 · v3 · submitted 2006-01-10 · 💻 cs.LO · cs.CR

Using First-Order Logic to Reason about Policies

classification 💻 cs.LO cs.CR
keywords first-orderlogicpoliciesfragmentpolicyquestionsreasonaccess
0
0 comments X
read the original abstract

A policy describes the conditions under which an action is permitted or forbidden. We show that a fragment of (multi-sorted) first-order logic can be used to represent and reason about policies. Because we use first-order logic, policies have a clear syntax and semantics. We show that further restricting the fragment results in a language that is still quite expressive yet is also tractable. More precisely, questions about entailment, such as `May Alice access the file?', can be answered in time that is a low-order polynomial (indeed, almost linear in some cases), as can questions about the consistency of policy sets.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.