1
Towards Automatic Update
- f Access Control Policy
Towards Automatic Update of Access Control Policy Jinwei Hu, Yan - - PowerPoint PPT Presentation
Towards Automatic Update of Access Control Policy Jinwei Hu, Yan Zhang, Ruixuan Li Huazhong University of Science and Technology, Wuhan, China University of Western Sydney, Sydney, Australia jwhu@hust.edu.cn 1 Contents Motivations and
1
2
3
4
5
specify update constraints
perform some operations check system and constraints constraints violated? update achieved? give up? end
yes yes yes no no no
undo operations Is the update achievable at atll? Are all changes necessary?
6
7
8
9
1 0
1 1
1 2
1 3
1 4
1 5
… … gap gap difference
qualified states
s1 s2 W hich update is better, s1 or s2 ?
1 6
1 7
1 8
Property holds. Property fails; A counter‐example is generated. System Property
1 9
Property holds. Property fails; A counter‐example is generated. RBAC System Property: Requested state is never reachable. update achievable? No. Requested state is never reachable. Yes. Requested state is not never reachable, and can be constructed from the counter- example.
2 0
Update request
simplified request
NuSMV Programs
Checking results
Reports
2 1
NuSMV Programs
Update request
simplified request
2 2
… … difference
qualified states
s1 s2 s3
Updating algorithm
2 3
… … difference
qualified states
s1 s2 s3
Updating algorithm
2 4
… … difference
qualified states
s1 s2 s3
Updating algorithm
2 5
… … difference
qualified states
s1 s2 s3
Updating algorithm No update report
2 6
2 7
2 8