Abstract:
We present a constructive authorization logic where the meanings of connectives are defined by their associated inference rules. This ensures that the logical reading of access control policies expressed in the logic and their implementation coincide. We study the proof-theoretic consequences of our design including cut-elimination and two non-interference properties that allow administrators to explore the correctness of their policies by establishing that for a given policy, assertions made by certain principals will not affect the truth of assertions made by others.
Citations
|
394
|
Untersuchungen über das Logische Schliessen
– Gentzen
- 1935
|
|
253
|
A calculus for access control in distributed systems
– Abadi, Burrows, et al.
- 1993
|
|
165
|
A core calculus of dependency
– Abadi, Banerjee, et al.
- 1999
|
|
128
|
Delegation Logic: A logic-based approach to distributed authorization
– Li, Grosof, et al.
- 2003
|
|
125
|
Proof-carrying authentication
– Appel, Felten
- 1999
|
|
75
|
On SDSI’s linked local name spaces
– Abadi
- 1997
|
|
68
|
a logic-based security language
– Binder
- 2002
|
|
59
|
A logical framework for reasoning about access control models
– BERTINO, CATANIA, et al.
- 2001
|
|
57
|
Datalog with Constraints: A Foundation for Trust
– Li, Mitchell
|
|
48
|
Logic in Access Control
– Abadi
- 2003
|
|
43
|
Propositional lax logic
– Fairtlough, Mendler
- 1997
|
|
36
|
Distributed proving in access-control systems
– Bauer, Garriss, et al.
- 2005
|
|
22
|
Access Control for the Web via Proof-carrying Authorization
– Bauer
- 2003
|
|
20
|
Device-enabled authorization in the Grey system
– Bauer, Garriss, et al.
- 2005
|
|
12
|
A logic of access control
– Crampton, Loizou, et al.
|
|
8
|
Consumable credentials in logic-based access-control systems
– Bowers, Bauer, et al.
- 2007
|
|
2
|
A judgmental analysis of linear logic. Submitted. Extended version available as
– Chang, Chaudhuri, et al.
- 2003
|