TY - JOUR
T1 - A novel social network access control model using logical authorization language in cloud computing
AU - Ma, Li
AU - Tao, Lixin
AU - Gai, Keke
AU - Zhong, Yong
N1 - Publisher Copyright:
Copyright © 2016 John Wiley & Sons, Ltd.
PY - 2017/7/25
Y1 - 2017/7/25
N2 - Current rapid increasing implementations in data diversity, autonomy, and dynamic privilege management, fine-grained access controls in social networks have resulted in various challenges in applying existing access control models. The intercrossing relations lead to the complex access control system, which often brings risks when the system is updated or expanded. The implementations of cloud computing has further complicate the access controls due to multiple tenancies and service providers. We focus on this issue and propose a new social network access control model using logical authorization language, named as RuleSN, which can be efficiently used in cloud systems. This model provides high performance of authorization expressiveness and flexibility that can effectively describe relations of User to User (U2U), User to Resource (U2R), Resource to Resource (R2R) and attributes of users and resources. First, this paper elaborates the formal definitions of the RuleSN model. Second, we describe the model's authorization specification and verification policies and explain the syntax and semantics of the authorization language. Finally, the implementation, application, and expressiveness of the model discussed by examples.
AB - Current rapid increasing implementations in data diversity, autonomy, and dynamic privilege management, fine-grained access controls in social networks have resulted in various challenges in applying existing access control models. The intercrossing relations lead to the complex access control system, which often brings risks when the system is updated or expanded. The implementations of cloud computing has further complicate the access controls due to multiple tenancies and service providers. We focus on this issue and propose a new social network access control model using logical authorization language, named as RuleSN, which can be efficiently used in cloud systems. This model provides high performance of authorization expressiveness and flexibility that can effectively describe relations of User to User (U2U), User to Resource (U2R), Resource to Resource (R2R) and attributes of users and resources. First, this paper elaborates the formal definitions of the RuleSN model. Second, we describe the model's authorization specification and verification policies and explain the syntax and semantics of the authorization language. Finally, the implementation, application, and expressiveness of the model discussed by examples.
KW - access control
KW - cloud computing
KW - cybersecurity
KW - logical authorization language
KW - privilege management
KW - social network
UR - http://www.scopus.com/inward/record.url?scp=84982839137&partnerID=8YFLogxK
U2 - 10.1002/cpe.3893
DO - 10.1002/cpe.3893
M3 - Article
AN - SCOPUS:84982839137
SN - 1532-0626
VL - 29
JO - Concurrency Computation Practice and Experience
JF - Concurrency Computation Practice and Experience
IS - 14
M1 - e3893
ER -