We design a graph-based framework for the visualisation and analysis of obligations in access control policies. We consider obligation policies in CBACO, the category-based access control model, which has been shown to subsume many of the most well known access control such as MAC, DAC, RBAC. CBACO is an extension of the CBAC metamodel that deals with obligations. We describe the implementation of the proposed model in PORGY, a strategy driven graph-rewriting tool, based on the theory of port-graphs. CBACO policies allow for dynamic behavior in the modelled systems, which is implemented using the strategy language of PORGY.
翻译:我们为出入控制政策中的义务的可视化和分析设计了一个基于图表的框架,我们考虑CBACO的债务政策,即基于类别的出入控制模式,它包含许多最著名的出入控制,如MAC、DAC、RBAC。CBACO是CBAC处理义务的元模型的延伸。我们描述了在PORGY实施拟议模式的情况,PORGY是一个战略驱动的图表改写工具,它以港口制图理论为基础。CBACO政策允许模型系统中的动态行为,该系统使用PORGY的战略语言实施。