Skip to main navigation Skip to search Skip to main content

Toward practical authorization-dependent user obligation systems

  • Murillo Pontual
  • , Omar Chowdhury
  • , William H. Winsborough
  • , Ting Yu
  • , Keith Irwin
  • University of Texas at San Antonio
  • North Carolina State University
  • Winston-Salem State University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

9 Scopus citations

Abstract

Many authorization system models include some notion of obligation. Little attention has been given to user obligations that depend on and affect authorizations. However, to be usable, the system must ensure users have the authorizations they need when their obligations must be performed. Prior work in this area introduced accountability properties that ensure failure to fulfill obligations is not due to lack of required authorizations. That work presented inconclusive and purely theoretical results concerning the feasibility of maintaining accountability in practice. The results of the current paper include algorithms and performance analysis that support the thesis that maintaining accountability in a reference monitor is reasonable in many applications.

Original languageEnglish
Title of host publicationProceedings of the 5th International Symposium on Information, Computer and Communications Security, ASIACCS 2010
Pages180-191
Number of pages12
DOIs
StatePublished - 2010
Event5th ACM Symposium on Information, Computer and Communication Security, ASIACCS 2010 - Beijing, China
Duration: Apr 13 2010Apr 16 2010

Publication series

NameProceedings of the 5th International Symposium on Information, Computer and Communications Security, ASIACCS 2010

Conference

Conference5th ACM Symposium on Information, Computer and Communication Security, ASIACCS 2010
Country/TerritoryChina
CityBeijing
Period04/13/1004/16/10

Keywords

  • accountability
  • authorization systems
  • obligations
  • policy
  • RBAC

Fingerprint

Dive into the research topics of 'Toward practical authorization-dependent user obligation systems'. Together they form a unique fingerprint.

Cite this