A novel social network access control model using logical authorization language in cloud computing

Li Ma, Lixin Tao*, Keke Gai, Yong Zhong

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

5 Citations (Scopus)

Abstract

Current rapid increasing implementations in data diversity, autonomy, and dynamic privilege management, fine-grained access controls in social networks have resulted in various challenges in applying existing access control models. The intercrossing relations lead to the complex access control system, which often brings risks when the system is updated or expanded. The implementations of cloud computing has further complicate the access controls due to multiple tenancies and service providers. We focus on this issue and propose a new social network access control model using logical authorization language, named as RuleSN, which can be efficiently used in cloud systems. This model provides high performance of authorization expressiveness and flexibility that can effectively describe relations of User to User (U2U), User to Resource (U2R), Resource to Resource (R2R) and attributes of users and resources. First, this paper elaborates the formal definitions of the RuleSN model. Second, we describe the model's authorization specification and verification policies and explain the syntax and semantics of the authorization language. Finally, the implementation, application, and expressiveness of the model discussed by examples.

Original languageEnglish
Article numbere3893
JournalConcurrency Computation Practice and Experience
Volume29
Issue number14
DOIs
Publication statusPublished - 25 Jul 2017
Externally publishedYes

Keywords

  • access control
  • cloud computing
  • cybersecurity
  • logical authorization language
  • privilege management
  • social network

Fingerprint

Dive into the research topics of 'A novel social network access control model using logical authorization language in cloud computing'. Together they form a unique fingerprint.

Cite this