Link to the University of Pittsburgh Homepage
Link to the University Library System Homepage Link to the Contact Us Form

TBA: A hybrid of logic and extensional access control systems

Hinrichs, TL and Garrison, WC and Lee, AJ and Saunders, S and Mitchell, JC (2012) TBA: A hybrid of logic and extensional access control systems. In: UNSPECIFIED UNSPECIFIED, 198 - 213. ISBN 9783642294198

Accepted Version

Download (278kB) | Preview
[img] Plain Text (licence)
Download (1kB)


Logical policy-based access control models are greatly expressive and thus provide the flexibility for administrators to represent a wide variety of authorization policies. Extensional access control models, on the other hand, utilize simple data structures to better enable a less trained and non-administrative workforce to participate in the day-to-day operations of the system. In this paper, we formally study a hybrid approach, tag-based authorization (TBA ), which combines the ease of use of extensional systems while still maintaining a meaningful degree of the expressiveness of logical systems. TBA employs an extensional data structure to represent metadata tags associated with subjects and objects, as well as a logical language for defining the access control policy in terms of those tags. We formally define TBA and introduce variants that include tag ontologies and delegation. We evaluate the resulting system by comparing to well-known extensional and logical access control models. © 2012 Springer-Verlag.


Social Networking:
Share |


Item Type: Book Section
Status: Published
CreatorsEmailPitt UsernameORCID
Hinrichs, TL
Garrison, WCbill@cs.pitt.eduWCG6
Lee, AJadamlee@pitt.eduADAMLEE
Saunders, S
Mitchell, JC
Date: 23 July 2012
Date Type: Publication
Access Restriction: No restriction; Release the ETD for access worldwide immediately.
Journal or Publication Title: Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume: 7140 L
Page Range: 198 - 213
Event Type: Conference
DOI or Unique Handle: 10.1007/978-3-642-29420-4_13
Institution: University of Pittsburgh
Schools and Programs: Dietrich School of Arts and Sciences > Computer Science
Refereed: Yes
ISBN: 9783642294198
ISSN: 0302-9743
Date Deposited: 05 Dec 2012 20:03
Last Modified: 03 Sep 2022 11:58


Monthly Views for the past 3 years

Plum Analytics

Actions (login required)

View Item View Item