An access control model supporting periodicity constraints and temporal reasoning
- 1 September 1998
- journal article
- Published by Association for Computing Machinery (ACM) in ACM Transactions on Database Systems
- Vol. 23 (3) , 231-285
- https://doi.org/10.1145/293910.293151
Abstract
Access control models, such as the ones supported by commercial DBMSs, are not yet able to fully meet many application needs. An important requirement derives from the temporal dimension that permissions have in many real-world situations. Permissions are often limited in time or may hold only for specific periods of time. In this article, we present an access control model in which periodic temporal intervals are associated with authorizations. An authorization is automatically granted in the specified intervals and revoked when such intervals expire. Deductive temporal rules with periodicity and order constraints are provided to derive new authorizations based on the presence or absence of other authorizations in specific periods of time. We provide a solution to the problem of ensuring the uniqueness of the global set of valid authorizations derivable at each instant, and we propose an algorithm to compute this set. Moreover, we address issues related to the efficiency of access control by adopting a materialization approach. The resulting model provides a high degree of flexibility and supports the specification of several protection requirements that cannot be expressed in traditional access control models.Keywords
This publication has 8 references indexed in Scilit:
- DECENTRALIZED ADMINISTRATION FOR A TEMPORAL ACCESS CONTROL MODELInformation Systems, 1997
- A non-ground realization of the stable and well-founded semanticsTheoretical Computer Science, 1996
- A temporal access control mechanism for database systemsIEEE Transactions on Knowledge and Data Engineering, 1996
- Safe stratified datalog with integer order programsPublished by Springer Nature ,1995
- A calculus for access control in distributed systemsACM Transactions on Programming Languages and Systems, 1993
- A closed-form evaluation for Datalog queries with integer (gap)-order constraintsTheoretical Computer Science, 1993
- Authorizations in relational database management systemsPublished by Association for Computing Machinery (ACM) ,1993
- The well-founded semantics for general logic programsJournal of the ACM, 1991