XACML Extension for Graphs: Flexible Authorization Policy Specification and Datastore-independent Enforcement

06/22/2023
by   Aya Mohamed, et al.
0

The increasing use of graph-structured data for business- and privacy-critical applications requires sophisticated, flexible and fine-grained authorization and access control. Currently, role-based access control is supported in graph databases, where access to objects is restricted via roles. This does not take special properties of graphs into account such as vertices and edges along the path between a given subject and resource. In previous iterations of our research, we started to design an authorization policy language and access control model, which considers the specification of graph paths and enforces them in the multi-model database ArangoDB. Since this approach is promising to consider graph characteristics in data protection, we improve the language in this work to provide flexible path definitions and specifying edges as protected resources. Furthermore, we introduce a method for a datastore-independent policy enforcement. Besides discussing the latest work in our XACML4G model, which is an extension to the Extensible Access Control Markup Language (XACML), we demonstrate our prototypical implementation with a real case and give an outlook on performance.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/01/2019

PACLP: a fine-grained partition-based access control policy language for provenance

Even though the idea of partitioning provenance graphs for access contro...
research
01/07/2020

A fine-grained policy model for Provenance-based Access Control and Policy Algebras.pdf

A fine-grained provenance-based access control policy model is proposed ...
research
10/31/2021

A Graphical Framework for the Category-Based Metamodel for Access Control and Obligations

We design a graph-based framework for the visualisation and analysis of ...
research
09/21/2019

Graph Model Implementation of Attribute-Based Access Control Policies

Attribute-based access control (ABAC) promises a powerful way of formali...
research
08/19/2021

Decentralized Policy Information Points for Multi-Domain Environments

Access control models have been developed to control authorized access t...
research
01/11/2019

Distributed Access Control with Blockchain

The specification and enforcement of network-wide policies in a single a...
research
09/08/2018

An automated model-based test oracle for access control systems

In the context of XACML-based access control systems, an intensive testi...

Please sign up or login with your details

Forgot password? Click here to reset