ABAC with Group Attributes and Attribute Hierarchies Utilizing the Policy Machine
Title | ABAC with Group Attributes and Attribute Hierarchies Utilizing the Policy Machine |
Publication Type | Conference Paper |
Year of Publication | 2017 |
Authors | Bhatt, Smriti, Patwa, Farhan, Sandhu, Ravi |
Conference Name | Proceedings of the 2Nd ACM Workshop on Attribute-Based Access Control |
Publisher | ACM |
Conference Location | New York, NY, USA |
ISBN Number | 978-1-4503-4910-9 |
Keywords | attribute hierarchy, attribute-based access control, attribute-based encryption, Collaboration, group attributes, group hierarchy, Human Behavior, human factors, policy machine, policy-based governance, pubcrawl, Scalability |
Abstract | Attribute-Based Access Control (ABAC) has received significant attention in recent years, although the concept has been around for over two decades now. Many ABAC models, with different variations, have been proposed and formalized. Besides basic ABAC models, there are models designed with additional capabilities such as group attributes, group and attribute hierarchies and so on. Hierarchical relationship among groups and attributes enhances access control flexibility and facilitates attribute management and administration. However, implementation and demonstration of ABAC models in real-world applications is still lacking. In this paper, we present a restricted HGABAC (rHGABAC) model with user and object groups and group hierarchy. We then introduce attribute hierarchies in this model. We also present an authorization architecture for implementing rHGABAC utilizing the NIST Policy Machine (PM). PM allows to define attribute-based access control policies, however, the attributes in PM are different in nature than attributes in typical ABAC models as name-value pairs. We identify a policy configuration mechanism for our proposed model employing PM capabilities, and demonstrate use cases and their configuration and implementation in PM using our authorization architecture. |
URL | https://dl.acm.org/citation.cfm?doid=3041048.3041053 |
DOI | 10.1145/3041048.3041053 |
Citation Key | bhatt_abac_2017 |