EDBT 2026 Demo / reviewers in the wild / expert
Ravi S. Sandhu
dblp:s/RaviSSandhu · also Ravi Sandhu, Ravinderpal Singh Sandhu
· DBLP profile ↗
217ranked-venue papers
61as first author
20since 2021 · last 2024
0000-0002-3165-1813ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 180 · 48 first-author · 16 since 2021Human-computer interaction and ubiquitous computing · 10 · 3 first-authorDatabases, data management, data science and information retrieval · 8 · 4 first-authorComputer networks · 5 · 1 first-author · 1 since 2021Theory of computation · 5 · 5 first-authorApplied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 4 · 2 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | ZTA-IoT: A Novel Architecture for Zero-Trust in IoT Systems and an Ensuing Usage Control ModelabstractRecently, several researchers motivated the need to integrate Zero Trust (ZT) principles when designing and implementing authentication and authorization systems for IoT. An integrated Zero Trust IoT system comprises the network infrastructure (physical and virtual) and operational policies in place for IoT as a product of a ZT architecture plan. This article proposes a novel Zero Trust architecture for IoT systems called ZTA-IoT. Additionally, based on different types of interactions between various layers and components in this architecture, we present ZTA-IoT-ACF, an access control framework that recognizes different interactions that need to be controlled in IoT systems. Within this framework, the article then refines its focus to object-level interactions, i.e., interactions where the target resource is a device (equivalently a thing) or an information file generated or stored by a device. Building on the recently proposed Zero Trust score-based authorization framework (ZT-SAF), we develop the object-level Zero Trust score-based authorization framework for IoT systems, denoted as ZTA-IoT-OL-SAF, to govern access requests in this context. With this machinery in place, we finally develop a novel usage control model for users-to-objects and devices-to-objects interactions, denoted as UCON \(_{IoT}\) . We give formal definitions, illustrative use cases, and a proof-of-concept implementation of UCON \(_{IoT}\) . This article is a first step toward establishing a rigorous formally defined score-based access control framework for Zero Trust IoT systems. Safwa Ameer, Lopamudra Praharaj, Ravi S. Sandhu, Smriti Bhatt, Maanak Gupta |
ACM Trans. Priv. Secur. | 3 |
| 2023 | Utilizing The DLBAC Approach Toward a ZT Score-based Authorization for IoT SystemsabstractThe internet of Things (IoT) refers to a network of physical objects that are equipped with sensors, software, and other technologies in order to communicate with other devices and systems over the internet. IoT has emerged as one of the most important technologies of this century over the past few years. To ensure IoT systems' sustainability and security over the long term, several researchers lately motivated the need to incorporate the recently proposed zero trust (ZT) cybersecurity paradigm when designing and implementing access control models for IoT systems. This poster proposes a hybrid access control approach incorporating traditional and deep learning-based authorization techniques toward score-based ZT authorization for IoT systems. Safwa Ameer, Ram Krishnan, Ravi S. Sandhu, Maanak Gupta |
CODASPY | 3 |
| 2023 | Hybrid Approaches (ABAC and RBAC) Toward Secure Access Control in Smart Home IoTabstractSmart homes are interconnected homes in which a wide variety of digital devices with limited resources communicate with multiple users and among themselves using multiple protocols. The deployment of resource-limited devices and the use of a wide range of technologies expand the attack surface and position the smart home as a target for many potential security threats. Access control is among the top security challenges in smart home IoT. Several access control models have been developed or adapted for IoT in general, with a few specifically designed for the smart home IoT domain. Most of these models are built on the role-based access control (RBAC) model or the attribute-based access control (ABAC) model. However, recently some researchers demonstrated that the need arises for a hybrid model combining ABAC and RBAC, thereby incorporating the benefits of both models to better meet IoT access control challenges in general and smart homes requirements in particular. In this paper, we used two approaches to develop two different hybrid models for smart home IoT. We followed a role-centric approach and an attribute-centric approach to develop HyBAC$_{RC}$and HyBAC$_{AC}$, respectively. We formally define these models and illustrate their features through a use case scenario demonstration. We further provide a proof-of-concept implementation for each model in Amazon Web Services (AWS) IoT platform. Finally, we conduct a theoretical comparison between the two models proposed in this paper in addition to the EGRBAC model (RBAC model for smart home IoT) and HABAC model (ABAC model for smart home IoT), which were previously developed to meet smart homes’ challenges. Safwa Ameer, James O. Benson, Ravi S. Sandhu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Reachability Analysis for Attributes in ABAC With Group HierarchyabstractAttribute-based access control (ABAC) models are widely used to provide fine-grained and adaptable authorization based on the attributes of users, resources, and other relevant entities. Hierarchical group and attribute based access control (HGABAC) model was recently proposed which introduces the novel notion of attribute inheritance through group membership. GURAGwas subsequently proposed to provide an administrative model for user attributes in HGABAC, building upon the ARBAC97 and GURA administrative models. The GURA model uses administrative roles to manage user attributes. The reachability problem for the GURA model is to determine what attributes a particular user can acquire, given a predefined set of administrative rules. This problem has been previously analyzed in the literature. In this article, we study the user attribute reachability problem based on directly assigned attributes of the user and attributes inherited via group memberships. We first define a restricted form of GURAG, called rGURAGscheme, as a state transition system with multiple instances having different preconditions and provide reachability analysis for each of these schemes. In general, we show PSPACE-complete complexity for all rGURAGschemes. We further present polynomial time algorithms with empirical experimental evaluation to solve special instances of rGURAGschemes under restricted conditions. Maanak Gupta, Ravi S. Sandhu, Tanjila Mawla, James O. Benson |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Security and Privacy for Emerging IoT and CPS DomainsabstractThe proliferation of IoT and CPS technologies demand novel conceptual, foundational and applied cybersecurity solutions. The dynamic behaviour of these distributed systems augmented with physical and computational constraints of smart devices, require cybersecurity approaches for timely prevention and detection of attacks. This panel aims to discuss open challenges and highlight future research directions for cybersecurity in IoT and CPS. Elisa Bertino, Ravi S. Sandhu, Bhavani Thuraisingham, Indrakshi Ray, Wenjia Li, Maanak Gupta, Sudip Mittal |
CODASPY | 2 |
| 2022 | Toward Deep Learning Based Access ControlabstractA common trait of current access control approaches is the challenging need to engineer abstract and intuitive access control models. This entails designing access control information in the form of roles (RBAC), attributes (ABAC), or relationships (ReBAC) as the case may be, and subsequently, designing access control rules. This framework has its benefits but has significant limitations in the context of modern systems that are dynamic, complex, and large-scale, due to which it is difficult to maintain an accurate access control state in the system for a human administrator. This paper proposes Deep Learning Based Access Control (DLBAC) by leveraging significant advances in deep learning technology as a potential solution to this problem. We envision that DLBAC could complement and, in the long-term, has the potential to even replace, classical access control models with a neural network that reduces the burden of access control model engineering and updates. Without loss of generality, we conduct a thorough investigation of a candidate DLBAC model, called DLBAC_alpha, using both real-world and synthetic datasets. We demonstrate the feasibility of the proposed approach by addressing issues related to accuracy, generalization, and explainability. We also discuss challenges and future research directions. Mohammad Nur Nobi, Ram Krishnan, Yufei Huang 0001, Mehrnoosh Shakarami, Ravi S. Sandhu |
CODASPY | 5 |
| 2022 | Administration of Machine Learning Based Access Control
Mohammad Nur Nobi, Ram Krishnan, Yufei Huang 0001, Ravi S. Sandhu |
ESORICS (2) | 4 |
| 2022 | BlueSky: Towards Convergence of Zero Trust Principles and Score-Based Authorization for IoT Enabled Smart SystemsabstractZero trust (ZT) is the term for an evolving set of cybersecurity paradigms that move defenses from static, network-based perimeters to focus on users, assets, and resources. It assumes no implicit trust is granted to assets or user accounts based solely on their physical or network location. We have billions of devices in IoT ecosystems connected to enable smart environments, and these devices are scattered around different locations, sometimes multiple cities or even multiple countries. Moreover, the deployment of resource-constrained devices motivates the integration of IoT and cloud services. This adoption of a plethora of technologies expands the attack surface and positions the IoT ecosystem as a target for many potential security threats. This complexity has outstripped legacy perimeter-based security methods as there is no single, easily identified perimeter for different use cases in IoT. Hence, we believe that the need arises to incorporate ZT guiding principles in workflows, systems design, and operations that can be used to improve the security posture of IoT applications. This paper motivates the need to implement ZT principles when developing access control models for smart IoT systems. It first provides a structured mapping between the ZT basic tenets and the PEI framework when designing and implementing a ZT authorization system. It proposes the ZT authorization requirements framework (ZT-ARF), which provides a structured approach to authorization policy models in ZT systems. Moreover, it analyzes the requirements of access control models in IoT within the proposed ZT-ARF and presents the vision and need for a ZT score-based authorization framework (ZT-SAF) that is capable of maintaining the access control requirements for ZT IoT connected systems. Safwa Ameer, Maanak Gupta, Smriti Bhatt, Ravi S. Sandhu |
SACMAT | 4 |
| 2022 | BlueSky: Activity Control: A Vision for "Active" Security Models for Smart Collaborative SystemsabstractCyber physical ecosystem connects different intelligent devices over heterogeneous networks. Various operations are performed on smart objects to ensure efficiency and to support automation in smart environments. An Activity (defined by Gupta and Sandhu) reflects the current state of an object, which changes in response to requested operations. Due to multiple running activities on different objects, it is critical to secure collaborative systems considering run-time decisions impacted due to related activities (and other parameters) supporting active enforcement of access control decision. Recently, Gupta and Sandhu proposed Activity-Centric Access Control (ACAC) and discussed the notion of activity as a prime abstraction for access control in collaborative systems. The model provides an active security approach that considers activity decision factors such as authorizations, obligations, conditions, and dependencies among related device activities. This paper takes a step forward and presents the core components of an ACAC model and compares with other security models differentiating novel properties of ACAC. We highlight how existing models do not (or in limited scope) support 'active' decision and enforcement of authorization in collaborative systems. We propose a hierarchical structure for a family of ACAC models by gradually adding the properties related to notion of activity and discuss states of an activity. We highlight the convergence of ACAC with Zero Trust tenets to reflect how ACAC supports necessary security posture of distributed and connected smart ecosystems. This paper aims to gain a better understanding of ACAC in collaborative systems supporting novel abstractions, properties and requirements. Tanjila Mawla, Maanak Gupta, Ravi S. Sandhu |
SACMAT | 3 |
| 2022 | Secure V2V and V2I Communication in Intelligent Transportation Using CloudletsabstractIntelligent Transportation System (ITS) is a vision which offers safe, secure and smart travel experience to drivers. This futuristic plan aims to enable vehicles, roadside transportation infrastructures, pedestrian smart-phones and other devices to communicate with one another to provide safety and convenience services. Vehicle to Vehicle (V2V) and Vehicle to Infrastructure (V2I) communication in ITS offers ability to exchange speed, heading angle, position and other environment related conditions amongst vehicles and with surrounding smart infrastructures. In this intelligent setup, vehicles and users communicate and exchange data with random untrusted entities (like vehicles, smart traffic lights or pedestrians) whom they don’t know or have met before. The concerns of location privacy and secure communication further deter the adoption of this smarter and safe transportation. In this article, we present a secure and trusted V2V and V2I communication approach using edge infrastructures where instead of direct peer to peer communication, we introduce trusted cloudlets to authorize, check and verify the authenticity, integrity and ensure anonymity of messages exchanged in the system. Moving vehicles or road side infrastructure are dynamically connected to nearby cloudlets, where security policies can be implemented to sanitize or stop fake messages and prevent rogue vehicles to exchange messages with other vehicles. We also present a formal attribute-based model for V2V and V2I communication, called AB-ITS, along with proof of concept implementation of the proposed solution in AWS IoT platform. This cloudlet supported architecture complements direct V2V or V2I communication, and serves important use cases such as accident or ice-threat warning and other safety applications. Performance metrics of our proposed architecture are also discussed and compared with existing ITS technologies. Maanak Gupta, James O. Benson, Farhan Patwa, Ravi S. Sandhu |
IEEE Trans. Serv. Comput. | 4 |
| 2021 | Formal Analysis of ReBAC Policy Mining FeasibilityabstractRelationship-Based Access Control (ReBAC) expresses authorization in terms of various direct and indirect relationships amongst entities, most commonly between users. The need for ReBAC policy mining arises when an existing access control system is reformulated in ReBAC. This paper considers the feasibility of ReBAC policy mining in context of user to user authorization, such as arises in various social and business contexts. In accordance with the policy mining literature, we assume that complete data is provided regarding user to user authorizations for a given user set, along with complete relationship data amongst these users comprising a labeled relationship graph. A ReBAC policy language is also specified. ReBAC policy mining seeks to formulate a ReBAC policy with the given policy language and relationship graph, which is exactly equivalent to the given authorizations. ReBAC policy mining feasibility problem asks whether such a policy exists and if so to provide the policy. We investigate this problem in context of different ReBAC policy languages which differ in the relationships, inverse relationships and non-relationships that can be used to build the policy. We develop a feasibility detection algorithm and analyze its complexity. We show that our policy languages are progressively more expressive as we introduce additional capability. In case of infeasibility, various solution approaches are discussed. Shuvra Chakraborty, Ravi S. Sandhu |
CODASPY | 2 |
| 2021 | On Feasibility of Attribute-Aware Relationship-Based Access Control Policy Mining
Shuvra Chakraborty, Ravi S. Sandhu |
DBSec | 2 |
| 2021 | Access Control Policy Generation from User Stories Using Machine Learning
John Heaps, Ram Krishnan, Yufei Huang 0001, Jianwei Niu 0001, Ravi S. Sandhu |
DBSec | 5 |
| 2021 | DUCE: Distributed Usage Control Enforcement for Private Data Sharing in Internet of Things
Na Shi, Ravi S. Sandhu, Qi Li 0002 |
DBSec | 3 |
| 2021 | Ruledger: Ensuring Execution Integrity in Trigger-Action IoT PlatformsabstractSmart home IoT systems utilize trigger-action platforms, e.g., IFTTT, to manage devices from various vendors. These platforms allow users to define rules for automatically triggering operations on devices. However, they may be abused by triggering malicious rule execution with forged IoT devices or events violating the execution integrity and the intentions of the users. To address this issue, we propose a ledger based IoT platform called Ruledger, which ensures the correct execution of rules by verifying the authenticity of the corresponding information. Ruledger utilizes smart contracts to enforce verifying the information associated with rule executions, e.g., the user and configuration information from users, device events, and triggers in the trigger-action platforms. In particular, we develop three algorithms to enable ledger-wallet based applications for Ruledger and guarantee that the records used for verification are stateful and correct. Thus, the execution integrity of rules is ensured even if devices and platforms in the smart home systems are compromised. We prototype Ruledger in a real IoT platform, i.e., IFTTT, and evaluate the performance with various settings. The experimental results demonstrate Ruledger incurs an average of 12.53% delay, which is acceptable for smart home systems. Jingwen Fan, Yi He 0020, Qi Li 0002, Ravi S. Sandhu |
INFOCOM | 5 |
| 2021 | Towards Activity-Centric Access Control for Smart Collaborative EcosystemsabstractThe ubiquitous presence of smart devices along with advancements in connectivity coupled with the elastic capabilities of cloud and edge systems have nurtured and revolutionized smart ecosystems. Intelligent, integrated cyber-physical systems offer increased productivity, safety, efficiency, speed and support for data driven applications beyond imagination just a decade ago. Since several connected devices work together as a coordinated unit to ensure efficiency and automation, the individual operations they perform are often reliant on each other. Therefore, it is important to control what functions or activities different devices can perform at a particular moment of time, and how they are related to each other. It is also important to consider additional factors such as conditions, obligation or mutability of activities, which are critical in deciding whether or not a device can perform a requested activity. In this paper, we take an initial step to propose and discuss the concept of Activity-Centric Access Control (ACAC) for smart and connected ecosystem. We discuss the notion of activity with respect to the collaborative and distributed yet integrated systems and identify the different entities involved along with the important factors to make an activity control decision. We outline a preliminary approach for defining activity control expressions which can be applied to different smart objects in the system. The main goal of this paper is to present the vision and need for the activity-centric approach for access control in connected smart systems, and foster discussion on the identified future research agenda. Maanak Gupta, Ravi S. Sandhu |
SACMAT | 2 |
| 2021 | Access Control Convergence: Challenges and Opportunities
Ravi S. Sandhu |
SECRYPT | 1 |
| 2021 | Secure V2V and V2I Communication in Intelligent Transportation using CloudletsabstractIntelligent Transportation System (ITS) is a vision which offers safe, secure and smart travel experience to drivers. This futuristic plan aims to enable vehicles, roadside transportation infrastructures, pedestrian smart-phones and other devices to communicate with one another to provide safety and convenience services. Vehicle to Vehicle (V2V) and Vehicle to Infrastructure (V2I) communication in ITS offers ability to exchange speed, heading angle, position and other environment related conditions amongst vehicles and with surrounding smart infrastructures. V2V will enable vehicles to exchange information about speed, location, direction, or brake status with other surrounding vehicles where receiving vehicles will aggregate these messages and make decisions. These on-board applications will warn drivers about accidents, over-speed, slow traffic ahead, aggressive driver, blind spot or a road hazard. V2I will enable road side units (RSUs) or traffic infrastructures to transmit information about bridge permissible height, merging traffic, work zone warning or road hazard detection to complement V2V applications. Maanak Gupta, James O. Benson, Farhan Patwa, Ravi S. Sandhu |
SERVICES | 4 |
| 2021 | Quantify Co-Residency Risks in the Cloud Through Deep LearningabstractCloud computing, while becoming more and more popular as a dominant computing platform, introduces new security challenges. When virtual machines are deployed in a cloud environment, virtual machine placement strategies can significantly affect the overall security risks of the entire cloud. In recent years, the attacks are specifically designed to co-locate with target virtual machines in the cloud. The virtual machine placement without considering the security risks may put the users, or even the entire cloud, in danger. In this article, we present a fine-grained model to quantify the risk level caused by co-residency. Using a large scale dataset collected from Microsoft Azure Platform, we profile the behavior patterns of normal service subscribers (tenants) using our proposed feature metrics. Tenants are clustered into multiple categories. After the baseline is established based on the normal behavior pattern, the derivation can be evaluated for each category and the high-risk group can be labeled accordingly. With the labeled datasets, a classification component and a quantification component are constructed to dynamically quantify the co-residency risks for a specific virtual machine. Our experimental results demonstrate the robustness of our model to the new data and the accuracy is verified by examination of F-score Matrix. Wanyu Zang, Meng Yu 0001, Ravi S. Sandhu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | An Attribute-Based Access Control for Cloud Enabled Industrial Smart VehiclesabstractSmart cities' vision will encompass connected industrial vehicles, which will offer data-driven and intelligent services to the user. Such interaction within dispersed connected objects are sometimes referred as the industrial Internet-of-Vehicles (IIoV). The prime motivation of an intelligent transportation system (ITS) is ensuring the safety of the drivers and offering a comfortable experience to the user. However, such complex infrastructures opens broad attack surfaces to the adversaries, which can remotely exploit and control the critical mechanics in the smart vehicles, including engine and brake systems. Security and privacy concerns are significant barriers to the wide adoption of this revolutionary technology that has to be addressed before a comprehensive implementation of the real vision of ITS. This article is a stepping stone to address access control issues in the IIoV ecosystem and propose a formal attribute-based access control system (referred to ITS-ABACG). The proposed model introduces the notion of groups, which are assigned to various smart entities based on the different attributes. It also offers the implementation of fine-grained security policies and considers individualized privacy preferences along with system-wide policies to accept or reject notification, alerts, and advertisements from different participating smart entities. We present the prototype implementation of our proposed model in the Amazon Web Services IoT platform together with extensive performance to reflect the practicality and wide-scale adoption of the proposed system. Maanak Gupta, Feras M. Awaysheh, James O. Benson, Mamoun Alazab, Farhan Patwa, Ravi S. Sandhu |
IEEE Trans. Ind. Informatics | 6 |
| 2020 | ABAC-CC: Attribute-Based Access Control and Communication Control for Internet of ThingsabstractInternet of Things (IoT) is revolutionizing the capabilities of the Internet with billions of connected devices in the cyberspace. These devices are commonly referred to as smart things enabling smart environments, such as Smart Home, Smart Health, Smart Transportation, and overall Smart Communities, together with key enabling technologies like Cloud Computing, Artificial Intelligence (AI) and Machine Learning (ML). Security and privacy are major concerns for today's diverse autonomous IoT ecosystem. Autonomous things and a large amount of data associated with things have fueled significant research in IoT access control and privacy in both academia and industry. To enable futuristic IoT with sustainable growth, dynamic access and communication control framework that adequately addresses security and privacy issues in IoT is inevitable. In this paper, we analyze the access and communication control requirements in Cloud-Enabled IoT (CE-IoT) and propose an attribute-based framework for access control and communication control, known as ABAC-CC, to secure accesses and communications (data flow) between various entities in the IoT architecture. We also introduce a novel Attribute-Based Communication Control (ABCC) model, which focuses on securing communications and data flow in IoT and enables users to define privacy policies using attributes of various entities. Furthermore, we analyze the applicability of ABAC-CC in specific IoT application domains, and finally, we present future research directions in the context of Cloud and Edge computing enabled IoT platforms. Smriti Bhatt, Ravi S. Sandhu |
SACMAT | 2 |
| 2020 | Safety Decidability for Pre-Authorization Usage Control with Identifier Attribute DomainsabstractSafety analysis is a fundamental problem in authorization models. Safety decidable models provide theoretical foundations for decentralized security administration. Attributes of objects are central to usage control authorization models. It has previously been shown that inclusion of a single infinite attribute leads to undecidable safety, even without any creation of objects. Therefore unrestricted inclusion of infinite attributes is not possible in a safety decidable model. On the other hand, it has recently been shown that the safety problem for the pre-authorization usage control sub-model with finite attribute domains, called PreUCONAfinite, is decidable even with unbounded object creation. A major limitation of finite attributes is the inability to link objects through attribute values in presence of unbounded object creation (since attributes that reference other objects must be infinite in this case). It would be desirable to have safety-decidable attribute-based models which include both finite and infinite attributes (necessarily with some restrictions). This paper develops a pre-authorization usage control sub-model, called PreUCONAid, with attribute domains solely comprised of infinite object identifiers with considerable restrictions on how these attributes can be updated. Safety decidability for PreUCONAidis proved by defining the notion of ω-equivalent usage configurations, and showing that the reachable set of v-equivalent usage configurations is computable and can be used to answer safety questions. The utility of such models in practice is illustrated by means of an example. The paper further shows that addition of even a single finite domain attribute to PreUCONAidresults in undecidable safety. These results indicate that combining finite and infinite attributes in a safety decidable model is a challenging task, which will likely require carefully crafted restrictions on updates to these attributes. The formulation of such a model remains an important open question. P. V. Rajkumar, Ravi S. Sandhu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2019 | Dynamic Groups and Attribute-Based Access Control for Next-Generation Smart CarsabstractSmart cars are among the essential components and major drivers of future cities and connected world. The interaction among connected entities in this vehicular internet of things (IoT) domain, which also involves smart traffic infrastructure, restaurant beacons, emergency vehicles, etc., offer several real-time applications and provide safer and pleasant driving experience to consumers. With more than 100 million lines of code and hundreds of sensors, these connected vehicles (CVs) expose a large attack surface, which can be remotely compromised and exploited by malicious attackers. Security and privacy are big concerns that deter the adoption of smart cars, which if not properly addressed will have grave implications with risk to human life and limb. In this paper, we present a formalized dynamic groups and attribute-based access control (ABAC) model (referred as CV-ABAC-G) for smart cars ecosystem, where the model not only considers system wide attributes-based security policies but also takes into account the individual user privacy preferences for allowing or denying service notifications, alerts and operations to on-board resources. Further, we introduce a novel notion of groups in vehicular IoT, which are dynamically assigned to moving entities like connected cars, based on their current GPS coordinates, speed or other attributes, to ensure relevance of location and time sensitive notification services, to provide administrative benefits to manage large numbers of entities, and to enable attributes inheritance for fine-grained authorization policies. We present proof of concept implementation of our model in AWS cloud platform demonstrating real-world uses cases along with performance metrics. Maanak Gupta, James O. Benson, Farhan Patwa, Ravi S. Sandhu |
CODASPY | 4 |
| 2019 | Online Malware Detection in Cloud Auto-scaling Systems Using Shallow Convolutional Neural Networks
Mahmoud Abdelsalam, Ram Krishnan, Ravi S. Sandhu |
DBSec | 3 |
| 2019 | Refresh Instead of Revoke Enhances Safety and Availability: A Formal Analysis
Mehrnoosh Shakarami, Ravi S. Sandhu |
DBSec | 2 |
| 2019 | IoT Passport: A Blockchain-Based Trust Framework for Collaborative Internet-of-ThingsabstractInternet-of-Things (IoT) is a rapidly-growing transformative expansion of the Internet with increasing influence on our daily life. Since the number of "things" is expected to soon surpass human population, control and automation of IoT devices has received considerable attention from academia and industry. Cross-platform collaboration is highly desirable for better user experience due to fragmentation of user needs and vendor products with time. Centralized approaches have been used to build federated trust among platforms and devices, but limit diversity and scalability. We propose a decentralized trust framework, called IoT Passport, for cross-platform collaborations using blockchain technology. IoT Passport is motivated by the familiar use of passports for international travel but with greater dynamism. It enables platforms to establish arbitrary trust relations with each other containing specific rules for intended collaborations, enforced by a combination of smart contracts. Each interaction among devices is signed by the participants and recorded on the blockchain. The records are utilized as attributes for authorization and as proofs of incentive plans. This approach incorporates the preferences of participating platforms and end users, and opens new avenues for collaborative edge computing as well as research on blockchain-based access control mechanism for IoT environments. Hongjuan Kang, Jingwen Fan, Qi Li 0002, Ravi S. Sandhu |
SACMAT | 5 |
| 2018 | Malware Detection in Cloud Infrastructures Using Convolutional Neural NetworksabstractA major challenge in Infrastructure as a Service (IaaS) clouds is its exposure to malware. Malware can spread rapidly within a datacenter and can cause major disruption to a cloud service provider and its clients. This paper introduces and discusses an effective malware detection approach in cloud infrastructure using Convolutional Neural Network (CNN), a deep learning approach. We initially employ a standard 2d CNN by training on metadata available for each of the processes in a virtual machine (VM) obtained by means of the hypervisor. We enhance the CNN classifier accuracy by using a novel 3d CNN (where an input is a collection of samples over a time interval), which greatly helps reduce mislabelled samples during data collection and training. Our experiments are performed on data collected by running various malware (mostly Trojans and Rootkits) on VMs. The malware used in our experiments are randomly selected. This reduces the selection bias of known-to-be highly active malware for easy detection. We demonstrate that our 2d CNN model reaches an accuracy of ≃ 79%, and our 3d CNN model significantly improves the accuracy to ≃ 90%. Mahmoud Abdelsalam, Ram Krishnan, Yufei Huang 0001, Ravi S. Sandhu |
IEEE CLOUD | 4 |
| 2018 | Access Control Model for Virtual Objects (Shadows) Communication for AWS Internet of ThingsabstractThe concept of Internet of Things (IoT) has received considerable attention and development in recent years. There have been significant studies on access control models for IoT in academia, while companies have already deployed several cloud-enabled IoT platforms. However, there is no consensus on a formal access control model for cloud-enabled IoT. The access-control oriented (ACO) architecture was recently proposed for cloud-enabled IoT, with virtual objects (VOs) and cloud services in the middle layers. Building upon ACO, operational and administrative access control models have been published for virtual object communication in cloud-enabled IoT illustrated by a use case of sensing speeding cars as a running example. Asma Alshehri, James O. Benson, Farhan Patwa, Ravi S. Sandhu |
CODASPY | 4 |
| 2018 | Authorization Framework for Secure Cloud Assisted Connected Cars and Vehicular Internet of ThingsabstractInternet of Things has become a predominant phenomenon in every sphere of smart life. Connected Cars and Vehicular Internet of Things, which involves communication and data exchange between vehicles, traffic infrastructure or other entities are pivotal to realize the vision of smart city and intelligent transportation. Vehicular Cloud offers a promising architecture wherein storage and processing capabilities of smart objects are utilized to provide on-the-fly fog platform. Researchers have demonstrated vulnerabilities in this emerging vehicular IoT ecosystem, where data has been stolen from critical sensors and smart vehicles controlled remotely. Security and privacy is important in Internet of Vehicles (IoV) where access to electronic control units, applications and data in connected cars should only be authorized to legitimate users, sensors or vehicles. In this paper, we propose an authorization framework to secure this dynamic system where interactions among entities is not pre-defined. We provide an extended access control oriented (E-ACO) architecture relevant to IoV and discuss the need of vehicular clouds in this time and location sensitive environment. We outline approaches to different access control models which can be enforced at various layers of E-ACO architecture and in the authorization framework. Finally, we discuss use cases to illustrate access control requirements in our vision of cloud assisted connected cars and vehicular IoT, and discuss possible research directions. Maanak Gupta, Ravi S. Sandhu |
SACMAT | 2 |
| 2017 | Clustering-Based IaaS Cloud MonitoringabstractOrganizations increasingly utilize cloud services such as Infrastructure as a Service (IaaS) where virtualized IT infrastructure are offered on demand by cloud providers. A major challenge for cloud providers is the security of virtual resources provided to its customers. In particular, a key concern is whether, for example, virtual machines (VMs) in the datacenter are performing tasks that are not expected of those machines. Given the scale of datacenters, continuous security monitoring of the virtual assets is essential to detect unexpected (and potentially malicious) behavior. In this paper, we develop a continuous monitoring framework for cloud IaaS. The proposed framework uses a modified version of sequential K-means clustering algorithm for anomaly detection based on variations in resource utilization that can be observed when cloud insiders or malware perform malicious tasks on cloud customers' VMs. Our approach assumes no prior knowledge of the installed applications on the VMs. Finally, our experiments are performed on data collected from our OpenStack (a popular open-source cloud IaaS software) testbed based on a standard 3-tier web architecture with the ability to scale-out (i.e., multiple copies of the server are spawned) and scale-back (i.e., the number of copies are reduced) on demand. The experiments are based on real-world as well as synthetically injected anomalies. Mahmoud Abdelsalam, Ram Krishnan, Ravi S. Sandhu |
CLOUD | 3 |
| 2017 | Classifying and Comparing Attribute-Based and Relationship-Based Access ControlabstractAttribute-based access control (ABAC) expresses authorization policy via attributes while relationship-based access control (ReBAC) does so via relationships. While ABAC concepts have been around for a long time, ReBAC is relatively recent emerging with its essential application in online social networks. Even as ABAC and ReBAC continue to evolve, there are conflicting claims in the literature regarding their comparison. It has been argued that ABAC can subsume ReBAC since attributes can encode relationships. Conversely there are claims that the multilevel (or indirect) relations of ReBAC bring fundamentally new capabilities. So far there is no rigorous comparative study of ABAC vis a vis ReBAC. This paper presents a comparative analysis of ABAC and ReBAC, and shows how various ReBAC features can be realized with different types of ABAC. We first identify several attribute types such as entity/non-entity and structured attributes that significantly influence ABAC or ReBAC expressiveness. We then develop a family of ReBAC models and a separate family of ABAC models based on the identified attribute types, with the goal of comparing the expressive power of these two model families. Further, we identify different dynamics of the models that are crucial for model comparison. We also consider different solutions for representing multilevel relationships with attributes. Finally, the ABAC and ReBAC model families are compared in terms of relative expressiveness and performance implications. Tahmina Ahmed, Ravi S. Sandhu |
CODASPY | 2 |
| 2017 | Object-Tagged RBAC Model for the Hadoop Ecosystem
Maanak Gupta, Farhan Patwa, Ravi S. Sandhu |
DBSec | 3 |
| 2017 | Safety of ABAC _\alpha Is Decidable
Tahmina Ahmed, Ravi S. Sandhu |
NSS | 2 |
| 2017 | Access Control Model for AWS Internet of Things
Smriti Bhatt, Farhan Patwa, Ravi S. Sandhu |
NSS | 3 |
| 2017 | Multi-Layer Authorization Framework for a Representative Hadoop Ecosystem DeploymentabstractApache Hadoop is a predominant software framework to store and process vast amount of data, produced in varied formats. Data stored in Hadoop multi-tenant data lake often includes sensitive data such as social security numbers, intelligence sources and medical particulars, which should only be accessed by legitimate users. Apache Ranger and Apache Sentry are important authorization systems providing fine-grained access control across several Hadoop ecosystem services. In this paper, we provide a comprehensive explanation for the authorization framework offered by Hadoop ecosystem, incorporating core Hadoop 2.x native access control features and capabilities offered by Apache Ranger, with prime focus on data services including Apache Hive and Hadoop 2.x core services. A multi-layer authorization system is discussed and demonstrated, reflecting access control for services, data, applications and infrastructure resources inside a representative Hadoop ecosystem instance. A concrete use case is discussed to underline the application of aforementioned access control points. We use Hortonworks Hadoop distribution HDP 2.5 to exhibit this multi-layer access control framework. Maanak Gupta, Farhan Patwa, James O. Benson, Ravi S. Sandhu |
SACMAT | 4 |
| 2017 | POSTER: Access Control Model for the Hadoop EcosystemabstractApache Hadoop is an important framework for fault-tolerant and distributed storage and processing of Big Data. Hadoop core platform along with other open-source tools such as Apache Hive, Storm, HBase offer an ecosystem to enable users to fully harness Big Data potential. Apache Ranger and Apache Sentry provide access control capabilities to several ecosystem components by offering centralized policy administration and enforcement through plugins. In this work we discuss the access control model for Hadoop ecosystem (referred as HeAC) used by Apache Ranger (release 0.6) and Sentry (release 1.7.0) along with Hadoop 2.x native authorization capabilities. This multi-layer model provides several access enforcement points to restrict unauthorized users to cluster resources. We further outline some preliminary approaches to extend the HeAC model consistent with widely accepted access control models. Maanak Gupta, Farhan Patwa, Ravi S. Sandhu |
SACMAT | 3 |
| 2017 | Mandatory Content Access Control for Privacy Protection in Information Centric NetworksabstractSeveral Information Centric Network (ICN) architectures have been proposed as candidates for the future Internet, aiming to solve several salient problems in the current IP-based Internet architecture such as mobility, content dissemination and multi-path forwarding. In general, security and privacy are considered as essential requirements in ICN. However, existing ICN designs lack built-in privacy protection for content providers (CPs), e.g., any router in an Internet Service Provider in ICN can cache any content, which may result in information leakage. In this paper, we propose Mandatory Content Access Control (MCAC), a distributed information flow control mechanism to enable a content provider to control which network nodes can cache its contents. In MCAC, a CP defines different security labels for different contents, and content routers check these labels to decide if a content object should be cached. To ensure correct enforcement of MCAC, we also propose a design of a trusted architecture by extending existing mainstream router architectures. We evaluate the performance of MCAC in the NS-3 simulator. The simulation results show that enforcing MCAC in routers does not introduce significant overhead in content forwarding. Qi Li 0002, Ravi S. Sandhu, Xinwen Zhang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2016 | POSTER: Security Enhanced Administrative Role Based Access Control ModelsabstractAdministrative rights are more powerful permissions and checking accountability of execution of admin rights is an important security measure. Most of the administrative RBAC models distribute rights to multiple administrators. Though such decentralized security management has difficulties in checking admin accountability, it is more efficient compared to centralized approach, particularly in large organizations. We introduced administrative obligations in ARBAC as a way to improve the accountability of admin users in the decentralized systems. The proposed approach would reduce the potential of security risk and improve accountability of security administrators. As the cloud and mobile applications are becoming integral part of business information systems, ensuring the accountability of admins play a vital role in system security. Obligations are well studied feature in the security literature and adding them into security administration would open up many possibilities for future developments in this direction. P. V. Rajkumar, Ravi S. Sandhu |
CCS | 2 |
| 2016 | Multi Cloud IaaS with Domain Trust in OpenStackabstractAs cloud services have been firmly accepted by enterprises, the current challenge is how to share these resources among increasing number of cloud platforms. Currently, cloud platforms such as OpenStack, the de facto open-source platform for cloud Infrastructure-as-a-Service (IaaS), offer limited cross-cloud access capabilities in their federation APIs. In this paper, we present a fine-grained cross-cloud domain-trust model enabling resource sharing between domains across distinct homogeneous clouds. We further present a formalized description of core multi-cloud OpenStack access control (MC-OSAC) with proposed domain trust extension. We have implemented a proof of concept with extending OpenStack identity and federation services to support cross-cloud domain trust. Our approach does not introduce any authorization overhead within current OpenStack federation model. Navid Pustchi, Farhan Patwa, Ravi S. Sandhu |
CODASPY | 3 |
| 2016 | A Comparison of Logical-Formula and Enumerated Authorization Policy ABAC Models
Prosunjit Biswas, Ravi S. Sandhu, Ram Krishnan |
DBSec | 2 |
| 2016 | Role-Centric Circle-of-Trust in Multi-tenant Cloud IaaS
Navid Pustchi, Ravi S. Sandhu |
DBSec | 2 |
| 2016 | Uni-ARBAC: A Unified Administrative Model for Role-Based Access Control
Prosunjit Biswas, Ravi S. Sandhu, Ram Krishnan |
ISC | 2 |
| 2016 | On the Relationship Between Finite Domain ABAM and PreUCON \mathrm _A A
Asma Alshehri, Ravi S. Sandhu |
NSS | 2 |
| 2016 | An Attribute-Based Protection Model for JSON Documents
Prosunjit Biswas, Ravi S. Sandhu, Ram Krishnan |
NSS | 2 |
| 2016 | The \mathrm GURA_G GURA G Administrative Model for User and Group Attribute Assignment
Maanak Gupta, Ravi S. Sandhu |
NSS | 2 |
| 2016 | Extended ReBAC Administrative Models with Cascading Revocation and Provenance SupportabstractRelationship-based access control (ReBAC) has been widely studied and applied in the domain of online social networks, and has since been extended to domains beyond social. Using ReBAC itself to manage ReBAC also becomes a natural research frontier, where we have two ReBAC administrative models proposed recently by Rizvi et al.[30] and Stoller[33]. In this paper, we extend these two ReBAC administrative models in order to apply ReBAC beyond online social networks, particularly where edges can have dependencies with each other and authorization for certain administrative operations requires provenance information. Basically, our policy specifications adopt the concepts of enabling precondition and applicability preconditions from Rizvi et al[30]. Then, we address several issues that need to be considered in order to properly execute operation effects, such as cascading revocation and integrity constraints on the relationship graph. With these extended features, we show that our administrative models can provide the administration capability of the MT-RBAC model originally designed for multi-tenant collaborative cloud systems[34]. Yuan Cheng 0002, Khalid Zaman Bijon, Ravi S. Sandhu |
SACMAT | 3 |
| 2016 | Panel Security and Privacy in the Age of Internet of Things: Opportunities and ChallengesabstractIn response to the new security and privacy concerns raised by emerging Internet of Things (IoT) technology, this panel discusses the current efforts and challenges to secure the IoT devices and to protect the integrity and privacy of users' data. Jianwei Niu 0001, Yier Jin, Adam J. Lee, Ravi S. Sandhu, Wenyuan Xu 0005 |
SACMAT | 4 |
| 2016 | An Access Control Model for Online Social Networks Using User-to-User RelationshipsabstractUsers and resources in online social networks (OSNs) are interconnected via various types of relationships. In particular, user-to-user relationships form the basis of the OSN structure, and play a significant role in specifying and enforcing access control. Individual users and the OSN provider should be enabled to specify which access can be granted in terms of existing relationships. In this paper, we propose a novel user-to-user relationship-based access control (UURAC) model for OSN systems that utilizes regular expression notation for such policy specification. Access control policies on users and resources are composed in terms of requested action, multiple relationship types, the starting point of the evaluation, and the number of hops on the path. We present two path checking algorithms to determine whether the required relationship path between users for a given access request exists. We validate the feasibility of our approach by implementing a prototype system and evaluating the performance of these two algorithms. Yuan Cheng 0002, Ravi S. Sandhu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2016 | Safety Decidability for Pre-Authorization Usage Control with Finite Attribute DomainsabstractThis paper considers the safety problem for the pre-authorization sub-model of the well-known$UCON_{ABC}$usage control model, that is,$Pre\_UCON_A$. It is shown that$Pre\_UCON_A$with finite attribute domains has decidable safety even if arbitrary object creation is allowed. This result eliminates the previously known restrictions for obtaining safety decidability in this context, which only allow a finite bounded number of objects to be created. Our result specifically permits unbounded object creation, so the set of objects is potentially infinite. In the proof, we show that the set of reachable protection tuples in infinite state$Pre\_UCON_A$models is finite and computable. We also provide a construction for decision procedure which answers the safety question by examining the reachable protection tuples. P. V. Rajkumar, Ravi S. Sandhu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2016 | A Provenance-Aware Access Control Framework with Typed ProvenanceabstractProvenance is a directed graph that captures historical information about data items in Provenance-Aware Systems (PAS). A variety of access control models and policy languages specific to PAS have been recently discussed in literature. However, it is still not clear how to efficiently specify provenance-aware access control policies and how to effectively enforce these policies with respect to complex provenance graph that can only be captured at run-time. To this end, we design and implement a provenance-aware access control framework with a layered architecture that features an abstract layer, including a Typed Provenance Model (TPM) and a set of TPM interpreters. TPM includes a set of abstract provenance types enabling efficient specification of provenance-aware policies. New provenance types can be composed of extant ones for specifying new policies. TPM interpreters can be integrated to enable the policy enforcement with respect to provenance graphs in different physical representations. By treating provenance types as special attributes, the proposed framework enables an adoption of provenance-aware access control in existing attribute-based access control frameworks, such as XACML-compliant ones. We implement the proposed framework by extending SUN's XACML implementation and show that it facilitates the specification of provenance-aware policies in XACML with minor extensions. We also analyze the performance of the proposed framework. Lianshan Sun, Dang Nguyen 0001, Ravi S. Sandhu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2015 | Attribute-Based Access Control Models and BeyondabstractThis talk will provide a perspective on attribute-based access control (ABAC). The ongoing authorization leap from rights to attributes offers numerous compelling benefits. Decisions about user, subject, object and context attributes can be made relatively independently and with suitable decentralization appropriate for each attribute. Policies can be formulated by security architects to translate from attributes to rights. Dynamic elements can be built into these policies so the outcomes of access control decisions automatically adapt to changing local and global circumstances. On the benefits side this leap is a maturation of authorization matching the needs of emerging cyber technologies and systems. On the risks side devolving attribute management may lead to attributes of questionable provenance and value, with attendant possibility of new channels for social engineering and malware attacks. We argue that the potential benefits will lead to pervasive deployment of attribute-based access control, and more generally attribute-based security. The cyber security research community has a responsibility to develop models, theories and systems which enable safe and chaos-free deployment of ABAC. This is a current grand challenge. Ravi S. Sandhu |
AsiaCCS | 1 |
| 2015 | Virtual Resource Orchestration Constraints in Cloud Infrastructure as a ServiceabstractIn an infrastructure as a service (IaaS) cloud, virtualized IT resources such as compute, storage and network are offered on demand by a cloud service provider (CSP) to its tenants (customers). A major problem for enterprise-scale tenants that typically obtain significant amount of resources from a CSP concerns orchestrating those resources in a secure manner. For instance, unlike configuring physical hardware, virtual resources in IaaS are configured using software, and hence prone to misconfigurations that can lead to critical security violations. Examples of such resource orchestration operations include creating virtual machines with appropriate operating system and software images depending on their purpose, creating networks, connecting virtual machines to networks, attaching a storage volume to a particular virtual machine, etc. In this paper, we propose attribute-based constraints specification and enforcement as a means to mitigate this issue. High-level constraints specified using attributes of virtual resources prevent resource orchestration operations that can lead to critical misconfigurations. Our model allows tenants to customize the attributes of their resources and specify fine-grained constraints. We further propose a constraint mining approach to automatically generate constraints once the tenants specify the attributes for virtual resources. We present our model, enforcement challenges, and its demonstration in OpenStack, the de facto open-source cloud IaaS software. Khalid Zaman Bijon, Ram Krishnan, Ravi S. Sandhu |
CODASPY | 3 |
| 2015 | Content Level Access Control for OpenStack Swift StorageabstractSwift, the object storage service from OpenStack cloud computing platform is used for storing, managing and retrieving large amounts of data. Inside Swift, uploaded files, also known as objects, are organized in containers. Objects inside a container are managed to be accessible or restricted from users through Access Control Lists (ACLs). Swift ACL, at the finest level, works on a Swift object enforcing who can or cannot access the object. Once an object is accessible to some one, he gets the full content of the object. Thus Swift ACL is an "all or nothing" approach. Prosunjit Biswas, Farhan Patwa, Ravi S. Sandhu |
CODASPY | 3 |
| 2015 | Secure Information and Resource Sharing in CloudabstractThe significant threats from information security breaches in cyber world is one of the most serious security problems. Organizations are facing growing number of sophisticated cyber-attacks every year. Efficient and secure sharing of attack and security information during cyber incident response plays increasingly significant role in fixing the problems as well as helping organizations recover fast. While traditional systems are slow and inefficient in sharing information and resources securely, cloud platform provides us a considerable convenience to facilitate the sharing. In this paper, we propose access control models for secure information and resource sharing (IARS) in cloud Infrastructure as a Service (IaaS). Ram Krishnan, Ravi S. Sandhu |
CODASPY | 3 |
| 2015 | MT-ABAC: A Multi-Tenant Attribute-Based Access Control Model with Tenant Trust
Navid Pustchi, Ravi S. Sandhu |
NSS | 2 |
| 2015 | Mitigating Multi-Tenancy Risks in IaaS Cloud Through Constraints-Driven Virtual Resource SchedulingabstractA major concern in the adoption of cloud infrastructure-as-a-service (IaaS) arises from multi-tenancy, where multiple tenants share the underlying physical infrastructure operated by a cloud service provider. A tenant could be an enterprise in the context of a public cloud or a department within an enterprise in the context of a private cloud. Enabled by virtualization technology, the service provider is able to minimize cost by providing virtualized hardware resources such as virtual machines, virtual storage and virtual networks, as a service to multiple tenants where, for instance, a tenant's virtual machine may be hosted in the same physical server as that of many other tenants. It is well-known that separation of execution environment provided by the hypervisors that enable virtualization technology has many limitations. In addition to inadvertent misconfigurations, a number of attacks have been demonstrated that allow unauthorized information flow between virtual machines hosted by a hypervisor on a given physical server. In this paper, we present attribute-based constraints specification and enforcement as a mechanism to mitigate such multi-tenancy risks that arise in cloud IaaS. We represent relevant properties of virtual resources (e.g., virtual machines, virtual networks, etc.) as their attributes. Conflicting attribute values are specified by the tenant or by the cloud IaaS system as appropriate. The goal is to schedule virtual resources on physical resources in a conflict-free manner. The general problem is shown to be NP-complete. We explore practical conflict specifications that can be efficiently enforced. We have implemented a prototype for virtual machine scheduling in OpenStack, a widely-used open-source cloud IaaS software, and evaluated its performance overhead, resource requirements to satisfy conflicts, and resource utilization. Khalid Zaman Bijon, Ram Krishnan, Ravi S. Sandhu |
SACMAT | 3 |
| 2015 | Multi-tenancy authorization models for collaborative cloud servicesabstractSummary The cloud service model intrinsically caters to multiple tenants, most obviously not only in public clouds but also in private clouds for large organizations. Currently, most cloud service providers isolate user activities and data within a single tenant boundary with no or minimum cross‐tenant interaction. It is anticipated that this situation will evolve soon to foster cross‐tenant collaboration supported by Authorization as a Service. At present, there is no widely accepted model for cross‐tenant authorization. Recently, Caleroet al.informally presented a multi‐tenancy authorization system (MTAS), which extends the well‐known role‐based access control model by building trust relations among collaborating tenants. In this paper, we formalize this MTAS model and propose extensions for finer‐grained cross‐tenant trust. We also develop an administration model for MTAS. We demonstrate the utility and practical feasibility of MTAS by means of an example policy specification in extensible access control markup language. To further test the metrics of the model, we develop a prototype system and conduct experiments on it. The result shows that the prototype has 12‐ms policy decision overhead on average and is scalable. We anticipate that researchers will develop additional multi‐tenant authorization models before eventual consolidation and convergence to standard industry practice. Copyright © 2014 John Wiley & Sons, Ltd. Ravi S. Sandhu, Qi Li 0002 |
Concurr. Comput. Pract. Exp. | 2 |
| 2015 | LIVE: Lightweight Integrity Verification and Content Access Control for Named Data NetworkingabstractNamed data networking (NDN) is a new paradigm for the future Internet wherein interest and data packets carry content names rather than the current IP paradigm of source and destination addresses. Security is built into NDN by embedding a public key signature in each data packet to enable verification of authenticity and integrity of the content. However, existing heavyweight signature generation and verification algorithms prevent universal integrity verification among NDN nodes, which may result in content pollution and denial of service attacks. Furthermore, caching and location-independent content access disables the capability of a content provider to control content access, e.g., who can cache a content and which end user or device can access it. We propose a lightweight integrity verification (LIVE) architecture, an extension to the NDN protocol, to address these two issues seamlessly. LIVE enables universal content signature verification in NDN with lightweight signature generation and verification algorithms. Furthermore, it allows a content provider to control content access in NDN nodes by selectively distributing integrity verification tokens to authorized nodes. We evaluate the effectiveness of LIVE with open source CCNx project. Our paper shows that LIVE only incurs average 10% delay in accessing contents. Compared with traditional public key signature schemes, the verification delay is reduced by over 20 times in LIVE. Qi Li 0002, Xinwen Zhang, Qingji Zheng, Ravi S. Sandhu, Xiaoming Fu 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2015 | Fingerprint-Based Detection and Diagnosis of Malicious Programs in HardwareabstractIn today's Integrated Circuit industry, a foundry, an Intellectual Property provider, a design house, or a Computer Aided Design vendor may install a hardware Trojan on a chip which executes a malicious program such as one providing an information leaking back door. In this paper, we propose a fingerprint-based method to detect any malicious program in hardware. We propose a tamper-evident architecture (TEA) which samples runtime signals in a hardware system during the performance of a computation, and generates a cryptographic hash-based fingerprint that uniquely identifies a sequence of sampled signals. A hardware Trojan cannot tamper with any sampled signal without leaving tamper evidence such as a missing or incorrect fingerprint. We further verify fingerprints off-chip such that a hardware Trojan cannot tamper with the verification process. As a case study, we detect hardware-based code injection attacks in a SPARC V8 architecture LEON2 processor. Based on a lightweight block cipher called PRESENT, a TEA requires only a 4.5% area increase, while avoiding being detected by the TEA increases the area of a code injection hardware Trojan with a 1 KB ROM from 2.5% to 36.1% of a LEON2 processor. Such a low cost further enables more advanced tamper diagnosis techniques based on a concurrent generation of multiple fingerprints. Ravi S. Sandhu |
IEEE Trans. Reliab. | 2 |
| 2014 | Role and attribute based collaborative administration of intra-tenant cloud IaaSabstractCloud Infrastructure as a Service (IaaS), where traditional IT infrastructure resources such as compute, storage and networking are owned by a cloud service provider (CSP) and offered as on-demand virtual resources to customers (tenants), is the fastest maturing service model in cloud computing. The Ram Krishnan, Ravi S. Sandhu |
CollaborateCom | 3 |
| 2014 | Attribute-Aware Relationship-Based Access Control for Online Social Networks
Yuan Cheng 0002, Ravi S. Sandhu |
DBSec | 3 |
| 2014 | Adopting Provenance-Based Access Control in OpenStack Cloud IaaS
Dang Nguyen 0001, Ravi S. Sandhu |
NSS | 3 |
| 2014 | A Formal Model for Isolation Management in Cloud Infrastructure-as-a-Service
Khalid Zaman Bijon, Ram Krishnan, Ravi S. Sandhu |
NSS | 3 |
| 2014 | Extending OpenStack Access Control with Domain Trust
Ravi S. Sandhu |
NSS | 2 |
| 2014 | A roadmap for privacy-enhanced secure data provenance
Elisa Bertino, Gabriel Ghinita, Murat Kantarcioglu, Dang Nguyen 0001, Jae Park, Ravi S. Sandhu, Salmin Sultana, Bhavani Thuraisingham, Shouhuai Xu |
J. Intell. Inf. Syst. | 6 |
| 2013 | The science, engineering and business of cyber securityabstractI will use the rare opportunity of this keynote talk to give my perspective on the general state and future prospects for cyber security, and the consequences of this perspective with respect to cyber security research and education. The ambiguous status of computer science in modern academia has persisted through the thirty plus years of my career. Does it belong in the College of Science or the College of Engineering? How about the College of Business? Is it worthy of a separate College of its own? I believe this ambiguity is a manifestation of the fundamental difference between computer science relative to traditional sciences and engineering disciplines. The forces of science, engineering and business come together and reconcile in a particularly unique way in computer science, and within computer science cyber security brings additional peculiarities to this reconciliation. Ravi S. Sandhu |
CCS | 1 |
| 2013 | Engineering access control policies for provenance-aware systemsabstractProvenance is meta-data about how data items become what they are. A variety of provenance-aware access control models and policy languages have been recently discussed in the literature. However, the issue of eliciting access control requirements related to provenance and of elaborating them as provenance-aware access control policies (ACPs) has received much less attention. This paper explores the approach to engineering provenance-aware ACPs since the beginning of software development. Specifically, this paper introduces a typed provenance model (TPM) to abstract complex provenance graph and presents a TPM-centric process for identification, specification, and refinement of provenance-aware ACPs. We illustrate this process by means of a homework grading system. Lianshan Sun, Ravi S. Sandhu |
CODASPY | 3 |
| 2013 | A provenance-based access control model for dynamic separation of dutiesabstractDynamic Separation of Duties (DSOD) is a well-known and important concept in cyber security, which has been extensively studied in the literature. The published literature mostly assumes that necessary information for enabling DSOD constraints is readily available. As such, there has been little discussion on the tasks of capturing, storing, extracting, and utilizing necessary historical information. Since this information is often in the form of system events history, provenance data is naturally suitable as the source for DSOD-related information. Recently the notion of provenance-based access control (PBAC) has been formulated and a base PBAC model (PBACB) together with an underlying provenance data model has been formally specified [19], [22]. Unlike Role-based Access Control where DSOD is modeled as a constraint, PBACBdirectly maintains and utilizes the necessary information for DSOD enforcement. In this paper, we propose an enhanced model, PBACc, by extending both the provenance data model and the PBACBmodel to enforce various DSOD policy classes identified in the literature, and go beyond these to specify novel DSOD policy classes. A proof-of-concept prototype is implemented and evaluated to demonstrate the feasibility of our approach. Dang Nguyen 0001, Ravi S. Sandhu |
PST | 3 |
| 2013 | A multi-tenant RBAC model for collaborative cloud servicesabstractMost cloud services are built with multi-tenancy which enables data and configuration segregation upon shared infrastructures. In this setting, a tenant temporarily uses a piece of virtually dedicated software, platform, or infrastructure. To fully benefit from the cloud, tenants are seeking to build controlled and secure collaboration with each other. In this paper, we propose a Multi-Tenant Role-Based Access Control (MT-RBAC) model family which aims to provide fine-grained authorization in collaborative cloud environments by building trust relations among tenants. With an established trust relation in MT-RBAC, the trustee can precisely authorize cross-tenant accesses to the truster's resources consistent with constraints over the trust relation and other components designated by the truster. The users in the trustee may restrictively inherit permissions from the truster so that multi-tenant collaboration is securely enabled. Using SUN's XACML library, we prototype MT-RBAC models on a novel Authorization as a Service (AaaS) platform with the Joyent commercial cloud system. The performance and scalability metrics are evaluated with respect to an open source cloud storage system. The results show that our prototype incurs only 0.016 second authorization delay for end users on average and is scalable in cloud environments. Qi Li 0002, Ravi S. Sandhu |
PST | 3 |
| 2012 | A lattice interpretation of group-centric collaboration with expedient insidersabstractFor various reasons organizations need to collaborate with external consultants, e.g. domain specialists, on specific projects. Many security-oriented organizations deploy multi-level systems which enforce one directional information flow in a lattice of security labels. However, traditional lat Khalid Zaman Bijon, Tahmina Ahmed, Ravi S. Sandhu, Ram Krishnan |
CollaborateCom | 3 |
| 2012 | A User-to-User Relationship-Based Access Control Model for Online Social Networks
Yuan Cheng 0002, Ravi S. Sandhu |
DBSec | 3 |
| 2012 | A Unified Attribute-Based Access Control Model Covering DAC, MAC and RBAC
Ram Krishnan, Ravi S. Sandhu |
DBSec | 3 |
| 2012 | A provenance-based access control modelabstractExistence of data provenance information in a system raises at least two security-related issues. One is how provenance data can be used to enhance security in the system and the other is how to protect provenance data which might be more sensitive than the data itself. Recent data provenance-related access control literature mainly focuses on the latter issue of protecting provenance data. In this paper, we propose a novel provenance-based access control model that addresses the former objective. Using provenance data for access control to the underlying data facilitates additional capabilities beyond those available in traditional access control models. We utilize a notion of dependency as the key foundation for access control policy specification. Dependency-based policy provides simplicity and effectiveness in policy specification and access control administration. We show our model can support dynamic separation of duty, workflow control, origin-based control, and object versioning. The proposed model identifies essential components and concepts and provides a foundational base model for provenance-based access control. We further discuss possible extensions of the proposed base model for enhanced access controls. Dang Nguyen 0001, Ravi S. Sandhu |
PST | 3 |
| 2012 | The authorization leap from rights to attributes: maturation or chaos?abstractThe ongoing authorization leap from rights to attributes offers numerous compelling benefits. Decisions about user, subject, object and context attributes can be made relatively independently and with suitable decentralization appropriate for each attribute. Policies can be formulated by security architects to translate from attributes to rights. Dynamic elements can be built into these policies so the outcomes of access control decisions automatically adapt to changing local and global circumstances. On the benefits side this leap is a maturation of authorization matching the needs of emerging cyber technologies and systems. On the risks side devolving attribute management may lead to attributes of questionable provenance and value, with attendant possibility of new channels for social engineering and malware attacks. We argue that the potential benefits will lead to pervasive deployment of attribute-based access control (ABAC), and more generally attribute-based security. The cyber security research community has a responsibility to develop models, theories and systems which enable safe and chaos-free deployment of ABAC. This is the current grand challenge for access control researchers. Ravi S. Sandhu |
SACMAT | 1 |
| 2012 | Speculations on the science of web user security
Ravi S. Sandhu |
Comput. Networks | 1 |
| 2012 | Editorial
Ravi S. Sandhu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2011 | An Attribute Based Framework for Risk-Adaptive Access Control ModelsabstractThe concept of risk-based adaptive access control (RAdAC, pronounced Raid-ack) has been recently introduced in the literature. It seeks to automatically (or semi-automatically) adjust security risk for providing access to resources accounting for operational needs, risk factors and situational factors. In order to make progress in this arena we need abstract models analogous to those that underlie the sustained and successful practice of discretionary, mandatory and role-based access control. Such models define a formal structure and components for policy specifications, while allowing for a variety of enforcement architectures and detailed implementation. In this paper we develop a novel approach to capture these characteristics of RAdAC using attribute-based access control. We further show that this RAdAC model can be expressed in the UCON usage control model with suitable extensions, and discuss how other UCON elements not used in this construction could beneficially improve the RAdAC vision. Savith Kandala, Ravi S. Sandhu, Venkata Bhamidipati |
ARES | 2 |
| 2011 | ACON: Activity-Centric Access Control for Social ComputingabstractWith increasing amount of sensitive user data stored in social computing systems (SCSs) and lack of consensus on how it should be protected under meaningful control by the average user, security and privacy has become a pressing problem that must be addressed. We propose the concept of user and SCS activity as a natural aspect of social computing which influences access control in a manner distinct to SCSs. We propose an activity-centric access control or Activity Control (ACON) framework for social computing to facilitate both privacy setting from user side and administration from SCS side. We further propose an ACONusermodel for user activity control and session management. We illustrate how the model captures the user activities using several SC examples. Ravi S. Sandhu, Yuan Cheng 0002 |
ARES | 2 |
| 2011 | The challenge of data and application security and privacy (DASPY): are we up to itabstractThis talk gives a personal perspective on the topic area of this new conference on data and application security and privacy, the difficult nature of the challenge we are confronting and possible research thrusts that may help us progress to an effective scientific discipline in this arena. Ravi S. Sandhu |
CODASPY | 1 |
| 2011 | On data provenance in group-centric secure collaborationabstractIn this paper, we explore data provenance in a group-centric secure collaboration environment. In collabora- tions, participating organizations are likely to want certain trustworthiness on the data that are shared from other or- ganizations and some assurance on how the shared data are used by user Dang Nguyen 0001, Ravi S. Sandhu |
CollaborateCom | 3 |
| 2011 | RT-based administrative models for community cyber security information sharingabstractWe develop a series of formal administrative models for recently proposed informal requirements for community cyber security information sharing. Traditional enterprise- oriented administrative models are not suitable for the highly dynamic and distributed nature of Ravi S. Sandhu, Khalid Zaman Bijon, Ram Krishnan |
CollaborateCom | 1 |
| 2011 | Roles in information security - A survey and classification of the research area
Ludwig Fuchs, Günther Pernul, Ravi S. Sandhu |
Comput. Secur. | 3 |
| 2011 | Group-Centric Secure Information-Sharing Models for Isolated GroupsabstractGroup-Centric Secure Information Sharing (g-SIS) envisions bringing users and objects together in a group to facilitate agile sharing of information brought in from external sources as well as creation of new information within the group. We expect g-SIS to be orthogonal and complementary to authorization systems deployed within participating organizations. The metaphors “secure meeting room” and “subscription service” characterize the g-SIS approach. The focus of this article is on developing the foundations of isolated g-SIS models. Groups are isolated in the sense that membership of a user or an object in a group does not affect their authorizations in other groups. Present contributions include the following: formal specification of core properties that at once help to characterize the family of g-SIS models and provide a “sanity check” for full policy specifications; informal discussion of policy design decisions that differentiate g-SIS policies from one another with respect to the authorization semantics of group operations; formalization and verification of a specific member of the family of g-SIS models; demonstration that the core properties are logically consistent and mutually independent; and identification of several directions for future extensions. The formalized specification is highly abstract. Besides certain well-formedness requirements that specify, for instance, a user cannot leave a group unless she is a member, it constrains only whether user-level read and write operations are authorized and it does so solely in terms of the history of group operations; join and leave for users and add, create, and remove for objects. This makes temporal logic one of the few formalisms in which the specification can be clearly and concisely expressed. The specification serves as a reference point that is the first step in deriving authorization-system component specifications from which a programmer with little security expertise could implement a high-assurance enforcement system for the specified policy. Ram Krishnan, Jianwei Niu 0001, Ravi S. Sandhu, William H. Winsborough |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2010 | Social Network-Based Botnet Command-and-Control: Emerging Threats and Countermeasures
Erhan J. Kartaltepe, Jose Andre Morales, Shouhuai Xu, Ravi S. Sandhu |
ACNS | 4 |
| 2010 | Towards a framework for cyber social status based trusted open collaborationabstractCollaboration takes place in both closed and open environments. While closed collaboration focuses on information or resource sharing amongst selected participants, open collaboration assumes and emphasizes that anyone can participate. In open collaboration, although participation is open to anyone Yuan Cheng 0002, Ravi S. Sandhu |
CollaborateCom | 3 |
| 2010 | Towards Secure Information Sharing models for community Cyber SecurityabstractIn this paper, we motivate the need for new models for Secure Information Sharing (SIS) in the specific domain of community cyber security. We believe that similar models will be applicable in numerous other domains. The term community in this context refers to a county or larger city size unit with Ravi S. Sandhu, Ram Krishnan, G. B. White |
CollaborateCom | 1 |
| 2010 | Analyzing and Exploiting Network Behaviors of Malware
Jose Andre Morales, Areej Al-Bataineh, Shouhuai Xu, Ravi S. Sandhu |
SecureComm | 4 |
| 2010 | Trustworthy Information: Concepts and Mechanisms
Shouhuai Xu, Haifeng Qian, Fengying Wang, Zhenxin Zhan, Elisa Bertino, Ravi S. Sandhu |
WAIM | 6 |
| 2010 | Editorial
Ravi S. Sandhu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2010 | Editorial
Ravi S. Sandhu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2009 | A First Step towards Characterizing Stealthy BotnetsabstractBotnets have become a top cyber threat. Existing studies on botnets have mainly focused on showing how to exploit certain characteristics of existing botnets to detect them. However, such detection mechanisms could be defeated by stealthy botnets that are designed to evade them. Therefore, it is important to understand the power of stealthy botnets so as to answer questions such as: What kinds of stealth techniques can survive what kinds of detection mechanisms? Towards the ultimate goal, this paper makes a first step with the aim to build fundamental understandings of stealthy botnet command and control (C&C). Justin Leonard, Shouhuai Xu, Ravi S. Sandhu |
ARES | 3 |
| 2009 | A Framework for Understanding BotnetsabstractBotnets have become a severe threat to the cyberspace. However, existing studies are typically conducted in an ad hoc fashion, by demonstrating specific analysis on captured bot programs or bot communication mechanisms so as to suggest means to counter them. Although such studies are important, another perhaps even more important problem that is largely left unaddressed is: how should we build a unified framework that can help us understand botnets in a systematic fashion? In this paper we make a first step towards the goal by presenting a framework, which especially suggests a general architecture that could be coupled with certain advanced techniques that have not been exploited in existing botnets. The framework also suggests a set of attributes that can be used to measure and compare botnets. Moreover, the dynamic nature of botnets (e.g., a victim machine may be powered-off during some time intervals) implies that a botnet, and thus its attributes, are stochastic in nature. This means that a meaningful comparison between botnet attributes should be based on the concept of stochastic order. Justin Leonard, Shouhuai Xu, Ravi S. Sandhu |
ARES | 3 |
| 2009 | A conceptual framework for Group-Centric secure information sharingabstractIn this paper, we propose a conceptual framework for developing a family of models for Group-Centric information sharing. The traditional approach to information sharing, characterized as Dissemination-Centric in this paper, focuses on attaching attributes and policies to an object (sometimes called "sticky policies") as it is disseminated from producers to consumers in a system. In contrast, Group-Centric sharing envisions bringing the subjects and objects together in a group to facilitate sharing. The metaphor is that of a secure meeting room where participants and information come together to "share" information for some common purpose. Another metaphor is that of the subscription model where, depending on policy, joining users may or may not be authorized to access past content. We argue that in such contexts, and in accordance with different application use cases, authorizations are influenced by the temporal ordering of subject and object group membership and by the precise nature of membership operations. For instance some subjects may only get future information added to the group while others may also be able to access previously added information. We develop a lattice of models based on variations of these basic membership operations, and discuss usage scenarios to illustrate practical applications of this lattice. Two principles guide Group-Centric models. First, "share but differentiate" which promotes sharing while differentiating user authorizations depending on temporal aspect of membership. Next, "groups within groups" which advocates relationships (such as a hierarchy) between multiple groups. In this paper, we confine our attention to read accesses in a single group. Ram Krishnan, Ravi S. Sandhu, Jianwei Niu 0001, William H. Winsborough |
AsiaCCS | 2 |
| 2009 | Towards a framework for group-centric secure collaborationabstractThe concept of groups is a natural aspect of most collaboration scenarios. Group-Centric Secure Information Sharing models (g-SIS) have been recently proposed in which users and objects are brought together to promote sharing and collaboration. Users may join, leave and re-join and objects may be ad Ram Krishnan, Ravi S. Sandhu, Jianwei Niu 0001, William H. Winsborough |
CollaborateCom | 2 |
| 2009 | The PEI framework for application-centric securityabstractThis paper motivates the fundamental importance of application context for security. It then gives an overview of the PEI framework for application-centric security and outlines some of the lessons learned in applying this framework. PEI stands for Policy, Enforcement and Implementation, signifying Ravi S. Sandhu |
CollaborateCom | 1 |
| 2009 | Assured Information Sharing Life CycleabstractThis paper describes our approach to assured information sharing. The research is being carried out under a MURI 9Multiuniversiyt Research Initiative) project funded by the Air Force Office of Scientific Research (AFOSR). The main objective of our project is: define, design and develop an Assured Information Sharing Lifecycle (AISL) that realizes the DoD's information sharing value chain. In this paper we describe the problem faced by the Department of Defense and our solution to developing an AISL System. Tim Finin, Anupam Joshi, Hillol Kargupta, Yelena Yesha, Joel Sachs, Elisa Bertino, Ninghui Li 0001, Chris Clifton, Eugene H. Spafford, Bhavani Thuraisingham, Murat Kantarcioglu, Alain Bensoussan 0001, Nathan Berg, Latifur Khan, Jiawei Han 0001, ChengXiang Zhai, Ravi S. Sandhu, Shouhuai Xu, Jim Massaro, Lada A. Adamic |
ISI | 17 |
| 2009 | A Characterization of the problem of secure provenance managementabstractData (or information) provenance has many important applications. However, prior work on data provenance management almost exclusively focused on the collection, representation, query, and storage of provenance data. In contrast, the security aspect of provenance management has not been understood nor adequately addressed. A natural question then is: What would a secure provenance management system - perhaps as an analogy to secure database management systems - look like? In this paper, we explore the problem space of secure provenance management systems with an emphasis on the security requirements for such systems, and characterize desired solutions for tackling the problem. We believe that this paper makes a significant step towards a comprehensive solution to the problem of secure provenance management. Shouhuai Xu, Qun Ni, Elisa Bertino, Ravi S. Sandhu |
ISI | 4 |
| 2009 | Foundations for group-centric secure information sharing modelsabstractWe develop the foundations for a theory of Group-Centric Secure Information Sharing (g-SIS), characterize a specific family of models in this arena and identify several directions in which this theory can be extended. Traditional approach to information sharing, characterized as Dissemination-Centric, focuses on attaching attributes and policies to an object as it is disseminated from producers to consumers in a system. In contrast, Group-Centric sharing envisions bringing the users and objects together in a group to facilitate sharing. The metaphors "secure meeting room" and "subscription service" characterize the Group-Centric approach where participants and information come together to share for some common purpose. Our focus in this paper is on semantics of group operations: Join and Leave for users and Add and Remove for objects, each of which can have several variations called types. Ram Krishnan, Ravi S. Sandhu, Jianwei Niu 0001, William H. Winsborough |
SACMAT | 2 |
| 2008 | QoS Aware Dependable Distributed Stream ProcessingabstractIn this paper we describe our approach for developing a QoS-aware, dependable execution environment for large-scale distributed stream processing applications. Distributed stream processing applications have strong timeliness and security demands. In particular, we address the following challenges: (1) propose a real-time dependable execution model by extending the component-based execution model with real-time and dependability properties, and (2) develop QoS-aware application composition and adaptation techniques that employ resource management strategies and security policies when discovering and selecting application components. Our approach enables us to develop a distributed stream processing environment that is predictable, secure, flexible and adaptable. Vana Kalogeraki, Dimitrios Gunopulos, Ravi S. Sandhu, Bhavani Thuraisingham |
ISORC | 3 |
| 2008 | ROWLBAC: representing role based access control in OWLabstractThere have been two parallel themes in access control research in recent years. On the one hand there are efforts to develop new access control models to meet the policy needs of real world application domains. In parallel, and almost separately, researchers have developed policy languages for access control. This paper is motivated by the consideration that these two parallel efforts need to develop synergy. A policy language in the abstract without ties to a model gives the designer little guidance. Conversely a model may not have the machinery to express all the policy details of a given system or may deliberately leave important aspects unspecified. Our vision for the future is a world where advanced access control concepts are embodied in models that are supported by policy languages in a natural intuitive manner, while allowing for details beyond the models to be further specified in the policy language. Tim Finin, Anupam Joshi, Lalana Kagal, Jianwei Niu 0001, Ravi S. Sandhu, William H. Winsborough, Bhavani Thuraisingham |
SACMAT | 5 |
| 2008 | Toward a Usage-Based Security Framework for Collaborative Computing SystemsabstractCollaborative systems such as Grids provide efficient and scalable access to distributed computing capabilities and enable seamless resource sharing between users and platforms. This heterogeneous distribution of resources and the various modes of collaborations that exist between users, virtual organizations, and resource providers require scalable, flexible, and fine-grained access control to protect both individual and shared computing resources. In this article we propose a usage control (UCON) based security framework for collaborative applications, by following a layered approach with policy, enforcement, and implementation models, called the PEI framework. In the policy model layer, UCON policies are specified with predicates on subject and object attributes, along with system attributes as conditional constraints and user actions as obligations. General attributes include not only persistent attributes such as role and group memberships but also mutable usage attributes of subjects and objects. Conditions in UCON can be used to support context-based authorizations in ad hoc collaborations. In the enforcement model layer, our novel framework uses a hybrid approach for subject attribute acquisition with both push and pull modes. By leveraging attribute propagations between a centralized attribute repository and distributed policy decision points, our architecture supports decision continuity and attribute mutability of the UCON policy model, as well as obligation evaluations during policy enforcement. As a proof-of-concept, we implement a prototype system based on our proposed architecture and conduct experimental studies to demonstrate the feasibility and performance of our approach. Xinwen Zhang, Masayuki Nakae, Michael J. Covington, Ravi S. Sandhu |
ACM Trans. Inf. Syst. Secur. | 4 |
| 2007 | SecureBus: towards application-transparent trusted computing with mandatory access controlabstractThe increasing number of software-based attacks has attracted substantial efforts to prevent applications from malicious interference. For example, Trusted Computing (TC) technologies have been recently proposed to provide strong isolation on application platforms. On the other hand, today pervasively available computing cycles and data resources have enabled various distributed applications that require collaboration among different application processes. These two conflicting trends grow in parallel. While much existing research focuses on one of these two aspects, a few authors have considered simultaneously providing strong isolation as well as collaboration convenience, particularly in the TC environment. However, none of these schemes is transparent. That is, they require modifications either of legacy applications or the underlying Operating System (OS).In this paper, we propose the SecureBus (SB) architecture, aiming to provide strong isolation and flexible controlled information flow and communication between processes at runtime. Since SB is application and OS transparent, existing applications can run without changes to commodity OS's. Furthermore, SB enables the enforcement of general access control policies, which is required but difficult to achieve for typical legacy applications. To study its feasibility and performance overhead, we have implemented a prototype system based on User-Mode Linux. Our experimental results show that SB can effectively achieve its design goals. Xinwen Zhang, Michael J. Covington, Songqing Chen, Ravi S. Sandhu |
AsiaCCS | 4 |
| 2007 | A Scalable and Secure Cryptographic Service
Shouhuai Xu, Ravi S. Sandhu |
DBSec | 2 |
| 2007 | Towards a Times-Based Usage Control Model
Baoxian Zhao, Ravi S. Sandhu, Xinwen Zhang, Xiaolin Qin |
DBSec | 2 |
| 2007 | Framework for Agent-Based Role DelegationabstractThis paper describes a framework for addressing the administration of role delegation introduced in the well-known role-based access control model (RBAC). More specifically, this paper describes how a third party, called an agent, can administer the delegation of roles on behalf of a user who is a member of a certain role and wishes to delegate his role to another user who belongs to another role. Furthermore, this paper describes a framework of reference to systematically address the diverse manifestations of the agent-based delegation, such as Role participant agent, non-role participant agent, static, and dynamic types of delegation and introduces an agent-based delegation model that illustrates delegation based on non-role participant delegation. Ezedin Barka, Ravi S. Sandhu |
ICC | 2 |
| 2007 | PEI models towards scalable, usable and high-assurance information sharingabstractSecure Information Sharing (SIS) or "share but protect" is a challenging and elusive problem both because of its broad scope and complexity ranging right from conception (objective and policy) to culmination (implementation). In this paper, we consider how to solve SIS challenges with three main and conflicting objectives: scalability, usability and high-assurance. In the context of SIS, high-assurance requires strong controls on the client. It is widely accepted that such controls cannot be entirely software-based. In this regard, we consider solutions based on commercially emerging hardware-rooted Trusted Computing Technology. For SIS, we argue super-distribution ("protect once and access wherever authorized") and off-line access are necessary to achieve scalability and usability. We limit super-distribution to occur within a group of Trusted Platform Module [1] or TPM-enabled machine. For simplicity, we assume all content that are distributed to be read-only. Drilling down, we discuss Policy, Enforcement and Implementation (PEI) models for SIS within a group (group-based SIS or g-SIS). Ram Krishnan, Ravi S. Sandhu, Kumar Ranganathan |
SACMAT | 2 |
| 2007 | Towards a VMM-based usage control framework for OS kernel integrity protectionabstractProtecting kernel integrity is one of the fundamental security objectives in building a trustworthy operating system (OS). For this end, a variety of approaches and systems have been proposed and developed. However, access control models used in most of these systems are not expressive enough to capture important security requirements such as continuous policy enforcement and mutable process and object attributes. Even worse, most existing protection mechanisms in these systems reside in the same space as the running OS, which unfortunately can be disabled or subverted after an attacker successfully exploits kernel-level vulnerabilities (or features) to compromise the OS kernel. The increasing number of kernel-level root kit attacks clearly demonstrates this threat. Xuxian Jiang, Ravi S. Sandhu, Xinwen Zhang |
SACMAT | 3 |
| 2006 | A general design towards secure ad-hoc collaborationabstractWe propose a general design for secure collaboration systems, which is underpinned with an access control policy model, an administrative scheme, and an enforcement scheme, based on the Type Usage Control (TUCON) model. TUCON is a generalized form of the usage control model (UCON) proposed recently. By utilizing mutable object attributes, UCON can reflect the dynamic nature of ad-hoc collaborations such as temporal and/or spatial usages. In TUCON, every object has an object type as a persistent attribute, which works as a name space that indicates an organization to which the object belongs. With object types, TUCON policies can distinctly control intra-organization and inter-organization information flows. This approach achieves the autonomy of collaborative teams as well as the mutual confidentiality of collaborating organizations. Masayuki Nakae, Xinwen Zhang, Ravi S. Sandhu |
AsiaCCS | 3 |
| 2006 | Secure information sharing enabled by Trusted Computing and PEI modelsabstractThe central goal of secure information sharing is to "share but protect" where the motivation to "protect" is to safeguard the sensitive content from unauthorized disclosure (in contrast to protecting the content to avoid loss of revenue as in retail Digital Rights Management). This elusive goal has been a major driver for information security for over three decades. Recently, the need for secure information sharing has dramatically increased with the explosion of the Internet and the convergence of outsourcing, offshoring and B2B collaboration in the commercial arena and the real-world demonstration of the tragic consequences of lack of information sharing in the national security arena. As technology has made the "share" aspect ever easier so has it increased the difficulty of enforcing the "protect" aspect. The central contribution of this paper is to show that the emergence of industrial strength Trusted Computing (TC) technology offers a range of novel solutions to the long-standing problem of secure information sharing. To this end we introduce a new framework of three layered models to analyze requirements and develop solutions, and demonstrate the application of this framework in context of TC and secure information sharing. The three layers are policy models (topmost), enforcement models (middle), and implementation models (bottom). Hence the name PEI models. At the policy model layer the secure information sharing space is divided into three categories called password based, device based, and credential based. For each of these policy categories various enforcement and implementation models can be developed. While we believe the PEI framework is relevant to security problems beyond secure information sharing, our goal in this paper is to demonstrate its application in this particular arena and identify questions for future research in this context. An essential benefit of PEI is that the three layers allow us to focus on the more important issues at a higher level of abstraction at the policy and enforcement layers, while leaving deep detail to the implementation layer. This paper focusses on the policy and enforcement layers with only passing mention of the implementation layer. Ravi S. Sandhu, Kumar Ranganathan, Xinwen Zhang |
AsiaCCS | 1 |
| 2006 | Safety analysis of usage control authorization modelsabstractThe usage control (UCON) model was introduced as a unified approach to capture a number of extensions for traditional access control models. While the policy specification flexibility and expressive power of this model have been studied in previous work, as a related and fundamental problem, the safety analysis of UCON has not been explored. This paper presents two fundamental safety results for UCONA, a sub-model of UCON only considering authorizations. In UCONA, an access control decision is based on the subject and/or the object attributes, which can be changed as the side-effects of using the access right, resulting in possible changes to future access control decisions. Hence the safety question in UCONA is all the more pressing since every access can potentially enable additional permissions due to the mutability of attributes in UCON. In this paper, first we show that the safety problem is in general undecidable. Then, we show that a restricted form of UCONA with finite attribute value domains and acyclic attribute creation relation has a decidable safety property. The decidable model maintains good expressive power as shown by specifying an RBAC system with a specific user-role assignment scheme and a DRM application with consumable rights. Xinwen Zhang, Ravi S. Sandhu, Francesco Parisi-Presicce |
AsiaCCS | 2 |
| 2006 | ROBAC: Scalable Role and Organization Based Access Control ModelsabstractIn RBAC, roles are typically created based on job functions inside an organization. Traditional RBAC does not scale up well for modeling security policies spanning multiple organizations. To solve this problem, a family of extended RBAC models called role and organization based access control (ROBAC) models is proposed and formalized in this paper. Two examples are used to motivate and demonstrate the usefulness of ROBAC. Comparison between ROBAC and other related RBAC models is given. We show that ROBAC can significantly reduce administration complexity for Web and Internet-based applications involving a large number of organizations. Some administrative issues for ROBAC are identified and discussed. Although the theoretical-expressive power of ROBAC is the same as that of RBAC, it is more succinct and intuitive to use ROBAC than to use RBAC when applications involve many organizations Xinwen Zhang, Ravi S. Sandhu |
CollaborateCom | 3 |
| 2006 | A usage-based authorization framework for collaborative computing systemsabstractCollaborative systems such as Grids provide efficient and scalable access to distributed computing capabilities and enable seamless resource sharing between users and platforms. This heterogeneous distribution of resources and the various modes of collaborations that exist between users, virtual organizations, and resource providers require scalable, flexible, and fine-grained access control to pro-tect both individual and shared computing resources. In this paper we propose a usage control (UCON) based authorization frame-work for collaborative applications. In our framework, usage con-trol policies are defined using subject and object attributes, along with system attributes as conditions. General attributes include not only persistent attributes such as role and group memberships, but also mutable usage attributes of subjects and objects. Conditions in UCON can be used to support context-based authorizations in ad-hoc collaborations. As a proof-of-concept we implement a pro-totype system based on our proposed architecture and conduct ex-perimental studies to demonstrate the feasibility and performance of our approach. Xinwen Zhang, Masayuki Nakae, Michael J. Covington, Ravi S. Sandhu |
SACMAT | 4 |
| 2006 | An effective role administration model using organization structureabstractRole-based access control (RBAC) is a well-accepted model for access control in an enterprise environment. When we apply RBAC model to large enterprises, effective role administration is a major issue. ARBAC97 is a well-known solution for decentralized RBAC administration. ARBAC97 authorizes administrative roles by means of role ranges and prerequisite conditions, where prerequisite conditions effectively work as a restricted pool for administrative roles to pick users or permissions. Although attractive and elegant in their own right, these mechanisms have significant shortcomings. In this paper, we propose an improved role administration model named ARBAC02 to overcome the weaknesses of ARBAC97. ARBAC02 introduces the concept of organization structure for defining user and permission pools independent of roles and role hierarchies, with a refined prerequisite condition specification. In addition, we present a bottom-up approach of permission-role administration in contrast to the top-down approach in ARBAC97. As a general solution, we illustrate the applications of organization structured-based security administration with other access control models, such as access control list model and lattice-based access control model. Sejong Oh, Ravi S. Sandhu, Xinwen Zhang |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2006 | Secure knowledge management: confidentiality, trust, and privacyabstractKnowledge management enhances the value of a corporation by identifying the assets and expertise as well as efficiently managing the resources. Security for knowledge management is critical as organizations have to protect their intellectual assets. Therefore, only authorized individuals must be permitted to execute various operations and functions in an organization. In this paper, secure knowledge management will be discussed, focusing on confidentiality, trust, and privacy. In particular, certain access-control techniques will be investigated, and trust management as well as privacy control for knowledge management will be explored Elisa Bertino, Latifur Khan, Ravi S. Sandhu, Bhavani Thuraisingham |
IEEE Trans. Syst. Man Cybern. Part A | 3 |
| 2005 | Peer-to-peer access control architecture using trusted computing technologyabstractIt has been recognized for some time that software alone does not provide an adequate foundation for building a high-assurance trusted platform. The emergence of industry-standard trusted computing technologies promises a revolution in this respect by providing roots of trust upon which secure applications can be developed. These technologies offer a particularly attractive platform for security in peer-to-peer environments. In this paper we propose a trusted computing architecture to enforce access control policies in such applications. Our architecture is based on an abstract layer of trusted hardware which can be constructed with emerging trusted computing technologies. A trusted reference monitor (TRM) is introduced beyond the trusted hardware. By monitoring and verifying the integrity and properties of running applications in a platform using the functions of trusted computing, the TRM can enforce various policies on behalf of object owners. We further extend this platform-based architecture to support user-based control policies, cooperating with existing services for user identity and attributes. This architecture and its refinements can be extended in future work to support general access control models such as lattice-based access control, role-based access control, and usage control. Ravi S. Sandhu, Xinwen Zhang |
SACMAT | 1 |
| 2005 | Database Security-Concepts, Approaches, and ChallengesabstractAs organizations increase their reliance on, possibly distributed, information systems for daily business, they become more vulnerable to security breaches even as they gain productivity and efficiency advantages. Though a number of techniques, such as encryption and electronic signatures, are currently available to protect data when transmitted across sites, a truly comprehensive approach for data protection must also include mechanisms for enforcing access control policies based on data contents, subject qualifications and characteristics, and other relevant contextual information, such as time. It is well understood today that the semantics of data must be taken into account in order to specify effective access control policies. Also, techniques for data integrity and availability specifically tailored to database systems must be adopted. In this respect, over the years, the database security community has developed a number of different techniques and approaches to assure data confidentiality, integrity, and availability. However, despite such advances, the database security area faces several new challenges. Factors such as the evolution of security concerns, the "disintermediation" of access to data, new computing paradigms and applications, such as grid-based computing and on-demand business, have introduced both new security requirements and new contexts in which to apply and possibly extend current approaches. In this paper, we first survey the most relevant concepts underlying the notion of database security and summarize the most well-known techniques. We focus on access control systems, on which a large body of research has been devoted, and describe the key access control models, namely, the discretionary and mandatory access control models, and the role-based access control (RBAC) model. We also discuss security for advanced data management systems, and cover topics such as access control for XML. We then discuss current challenges for database security and some preliminary approaches that address some of these challenges. Elisa Bertino, Ravi S. Sandhu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2005 | EditorialabstractNo abstract available. Ravi S. Sandhu |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2005 | Formal model and policy specification of usage controlabstractThe recent usage control model (UCON) is a foundation for next-generation access control models with distinguishing properties of decision continuity and attribute mutability. A usage control decision is determined by combining authorizations, obligations, and conditions, presented as UCON ABC core models by Park and Sandhu. Based on these core aspects, we develop a formal model and logical specification of UCON with an extension of Lamport's temporal logic of actions (TLA). The building blocks of this model include: (1) a set of sequences of system states based on the attributes of subjects, objects, and the system, (2) authorization predicates based on subject and object attributes, (3) usage control actions to update attributes and accessing status of a usage process, (4) obligation actions, and (5) condition predicates based on system attributes. A usage control policy is defined as a set of temporal logic formulas that are satisfied as the system state changes. A fixed set of scheme rules is defined to specify general UCON policies with the properties of soundness and completeness. We show the flexibility and expressive capability of this formal model by specifying the core models of UCON and some applications. Xinwen Zhang, Francesco Parisi-Presicce, Ravi S. Sandhu |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2004 | Mohammad A. Al-Kahtani, Ravi SandhuabstractRBAC has proven to be a flexible and useful access control model in practice. Rule-Based RBAC family of models was developed based on RBAC to overcome some of its limitations. One particular model of this family, which we call RB-RBAC-ve, introduces the concept of negative authorization to the RBAC arena. This paper provides a more detailed analysis of RB-RBAC-ve. The analysis includes user authorization, conflict among rules, conflict resolution polices, the impact of negative authorization on role hierarchies and enforcement architecture. Mohammad A. Al-Kahtani, Ravi S. Sandhu |
ACSAC | 2 |
| 2004 | Role-Based Delegation Model/ Hierarchical Roles (RBDM1)abstractThe basic idea behind delegation is that some active entity in a system delegates authority to another active entity in order to carry out some functions on behalf of the former. User delegation in RBAC is the ability of one user (called the delegating user) who is a member of the delegated role to authorize another user (called the delegate user) to become a member of the delegated role. This paper introduces a new model, which we consider it to be an extension of REDM0 [BS2000]. The central contribution of this paper is to introduce a new model, referred to as RBDM1 (role-based delegation model/ hierarchical roles), that uses the details from RBDM0, which was described in the literature by Barka and Sandhu [BS2000] to address the temporary delegation based on hierarchical roles. We formally defined a role-based delegation model based on hierarchical relationship between the roles involved. We also identified the different semantics that impact the can-delegate relation, we analyzed these semantics to determine which ones we consider as more appropriate in business today, thus allowed in our model, and provided a justification to why those selections are made. Ezedin Barka, Ravi S. Sandhu |
ACSAC | 2 |
| 2004 | Attribute Mutability in Usage ControlabstractThe notion of Usage Control (UCON) has been introduced recently to extend traditional access controls by including three decision factors called authorizations, obligations , and conditions . Usage control also recognize two important decision properties of continuity and mutability . In access control literature, an authorization decision is commonly made by utilizing some form of subject and object attributes. Identities, security labels and roles are some examples of attributes. Traditionally these attributes are assigned to subjects and objects by a security officer and can be modified only by administrative actions. However, in modern information systems these attributes are often required to be changed as a side effect of subject’s usage on object. This requirement of updates has been recognized and defined as mutability property in usage control. In this paper, we discuss issues of this attribute mutability and show how usage control can apply this mutability property in various traditional and modern access control policies. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Xinwen Zhang, Ravi S. Sandhu |
DBSec | 3 |
| 2004 | A Perspective on Graphs and Access Control Models
Ravi S. Sandhu |
ICGT | 1 |
| 2004 | Security for grid-based computing systems issues and challengesabstractGrid systems were initially developed for supporting scientific computations. Today, companies, users and researchers are looking at ways to use the Grid approach to commercial uses and for applications in many different areas. Security in grid systems however has not been much addressed and yet is an important prerequisite to really make grid systems usable in a variety of commercial applications.The goal of this panel is to explore relevant security issues, with special emphasis on access control, for grid-based computing systems. The panel will discuss security requirements that are specific to grid-based systems and set these systems apart from conventional distributed systems, and outline directions for future research. Questions addressed by the panel include the following ones: Elisa Bertino, Bruno Crispo, James B. D. Joshi, Wengliang (Kevin) Du, Ravi S. Sandhu |
SACMAT | 5 |
| 2004 | A logical specification for usage controlabstractRecently presented usage control (UCON) has been considered as the next generation access control model with distinguishing properties of decision continuity and attribute mutability. Ausage control decision is determined by combining authorizations, obligations, and conditions, presented as UCONABC core models by Park and Sandhu. Based on these core aspects, we develop afirst-order logic specification of UCON with Lamport's temporallogic of actions (TLA). The building blocks of this model include:(1) a sequence of states expressed by attributes of subjects, objects, and the system, (2) state predicates on subject andobject attributes, (3) pre-defined authorization actions performed by the security system and subjects, (4) obligation actions, and(5) condition predicates on system attributes. For a UCON model we define a set of temporal logic formulas that hold as usage control policies. We show the flexibility and expressive capability of this logic model by specifying the new features and core models of UCON. Xinwen Zhang, Francesco Parisi-Presicce, Ravi S. Sandhu |
SACMAT | 4 |
| 2004 | The UCONABC usage control modelabstractIn this paper, we introduce the family of UCON ABC models for usage control (UCON), which integrate Authorizations (A), oBligations (B), and Conditions (C) . We call these core models because they address the essence of UCON, leaving administration, delegation, and other important but second-order issues for later work. The term usage control is a generalization of access control to cover authorizations, obligations, conditions, continuity (ongoing controls), and mutability. Traditionally, access control has dealt only with authorization decisions on users' access to target resources. Obligations are requirements that have to be fulfilled by obligation subjects for allowing access. Conditions are subject and object independent environmental or system requirements that have to be satisfied for access. In today's highly dynamic, distributed environment, obligations and conditions are also crucial decision factors for richer and finer controls on usage of digital resources. Although they have been discussed occasionally in recent literature, most authors have been motivated from specific target problems and thereby limited in their approaches. The UCON ABC model integrates these diverse concepts in a unified framework. Traditional authorization decisions are generally made at the time of requests but hardly recognize ongoing controls for relatively long-lived access or for immediate revocation. Moreover, mutability issues that deal with updates on related subject or object attributes as a consequence of access have not been systematically studied.Unlike other studies that have targeted on specific problems or issues, the UCON ABC model seeks to enrich and refine the access control discipline in its definition and scope. UCON ABC covers traditional access controls such as mandatory, discretionary, and role-based access control. Digital rights management and other modern access controls are also covered. UCON ABC lays the foundation for next generation access controls that are required for today's real-world information and systems security. This paper articulates the core of this new area of UCON and develops several detailed models. Ravi S. Sandhu |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2003 | Two Efficient and Provably Secure Schemes for Server-Assisted Threshold Signatures
Shouhuai Xu, Ravi S. Sandhu |
CT-RSA | 2 |
| 2003 | Schema Based XML Security: RBAC Approach
Xinwen Zhang, Ravi S. Sandhu |
DBSec | 3 |
| 2003 | Induced role hierarchies with attribute-based RBACabstractThe Role-Based Access Control (RBAC) model is traditionally used to manually assign users to appropriate roles. When the service-providing enterprise has a massive customer base, assigning users to roles ought to be automated. RB-RBAC (Rule-Based RBAC) provides the mechanism to dynamically assign users to roles based on a finite set of authorization rules defined by the enterprise's security policy. These rules may have seniority relation among them, which induces a roles hierarchy. The main contribution of this paper is to explore the possible discrepancies between the Induced Roles Hierarchy and any existing roles hierarchy. The functional impact of existing discrepancies and ways of reconciling them are discussed. Mohammad A. Al-Kahtani, Ravi S. Sandhu |
SACMAT | 2 |
| 2003 | PBDM: a flexible delegation model in RBACabstractRole-based access control (RBAC) is recognized as an efficient access control model for large organizations. Most organizations have some business rules related to access control policy. Delegation of authority is among these rules. RBDM0 and RDM2000 models are recently published models for role-based delegation. They deal with user-to-user delegation. The unit of delegation in them is a role. But in many cases users may want to delegate a piece of permission from a role. This paper proposes a flexible delegation model named Permission-based Delegation Model (PBDM), which is built on the well known RBAC96 model. PBDM supports user-to-user and role-to-role delegations with features of multi-step delegation and multi-option revocation. It also supports both role and permission level delegation, which provides great flexibility in authority management. In PBDM, a security administrator specify the permissions that a user (delegator) has authority to delegate to others (delegatee), then the delegator creates one or more temporary delegation roles and assigns delegatees to particular roles. This gives us clear separation of security administration and delegation. Xinwen Zhang, Sejong Oh, Ravi S. Sandhu |
SACMAT | 3 |
| 2002 | A Model for Attribute-Based User-Role AssignmentabstractThe role-based access control (RBAC) model is traditionally used to manually assign users to appropriate roles, based on a specific enterprise policy, thereby authorizing them to use the roles' permissions. In environments where the service-providing enterprise has a huge customer base this task becomes formidable. An appealing solution is to automatically assign users to roles. The central contribution of this paper is to describe a model to dynamically assign users to roles based on a finite set of rules defined by the enterprise. These rules take into consideration the attributes of users and any constraints set forth by the enterprise's security policy. The model also allows dynamic revocation of assigned roles based on conditions specified in the security policy. The model provides a language to express these rules and defines a mechanism to determine seniority among different rules. The paper also shows how to use the model to express mandatory access controls (MAC). Mohammad A. Al-Kahtani, Ravi S. Sandhu |
ACSAC | 2 |
| 2002 | Making access control more usableabstractScope: a variety of things are expressed under the heading of access control: permission assignments, constraints, activations, transition, hierarchies, ect. What things really need to be expressed?Concepts: What modeling concepts are available to express these things? Where are we in understanding the usability of these models?Complexity-flexibility tradeoff: How do we make trade-offs between the flexibility of expression (expressive power) and applying more usable concepts? Can this be measured?Domain specificity: Improving ease of use often involves increasing the level of the specification using domain-specific techniques. What techniques are possible? How can we compare teh effectiveness of these techniques?Composition: How can the modularity of access control policies be leveraged? Is there any modularity?Completeness: How do we integrate access control effectively with support for audit and intrusion detection? Elisa Bertino, Trent Jaeger, Jonathan D. Moffett, Sylvia L. Osborn, Ravi S. Sandhu |
SACMAT | 5 |
| 2002 | A model for role administration using organization structureabstractRole-based access control (RBAC) is recognized as an excellent model for access control in an enterprise environment. In large enterprises, effective RBAC administration is a major issue. ARBAC97 is a well-known solution for decentralized RBAC administration. ARBAC97 authorizes administrative roles by means of role ranges' and prerequisite conditions'. Although attractive and elegant in their own right, we will see that these mechanisms have significant shortcomings.We propose an improved role administration model named ARBAC02 to overcome the weaknesses of ARBAC97. ARBAC02 adopts the organization unit for new user and permission pools independent of role or role hierarchy. It uses a refined prerequisite condition. In addition, we present a bottom-up approach to permission-role administration in contrast to the top-down approach of ARBAC97. Sejong Oh, Ravi S. Sandhu |
SACMAT | 2 |
| 2002 | Towards usage control models: beyond traditional access controlabstractIn this paper we develop the concept of Usage Control (UCON) that encompasses traditional access control, trust management, and digital rights management and goes beyond them in its definition and scope. While usage control concepts have been mentioned off and on in the security literature for some time, there has been no systematic treatment so far. By unifying these three areas UCON offers a promising approach for the next generation of access control. Traditional access control has focused on a closed system where all users are known and primarily utilizes a server-side reference monitor within the system. Trust management has been introduced to cover authorization for strangers in an open environment such as the Internet. Digital rights management has dealt with client-side control of digital information usage. Each of these areas is motivated by its own target problems. Innovations in information technology and business models are creating new security and privacy issues which require elements of all three areas. To deal with these in a systematic unified manner we propose the new UCON model. UCON enables finer-grained control over usage of digital objects than that of traditional access control policies and models. For example, print once as opposed to unlimited prints. Unlike traditional access control or trust management, it covers both centrally controllable environment and an environment where central control authority is not available. UCON also deals with privacy issues in both commercial and non-commercial environments. In this paper we first discuss access control, trust management, and digital rights management and describe general concepts of UCON in the information security discipline. Then we define components of the UCON model and discuss how authorizations and access controls can be applied in the UCON model. Next we demonstrate some applications of the UCON model and develop further details. We use several examples during these discussions to show the relevance and validity of our approach. Finally we identify some open research issues. Ravi S. Sandhu |
SACMAT | 2 |
| 2001 | Engineering of Role/Permission AssignmentsabstractWe develop a model for engineering role-permission assignment. Our model builds upon the well-known RBAC96 model. Assigning permissions to roles is considered too complex an activity to accomplish directly. Instead we advocate breaking down this process into a number of steps. We specifically introduce the concept of jobs, work-patterns, and tasks to facilitate role-permission assignment into a series of smaller steps. We describe methodologies for using this model in two different ways. In a top-down approach, roles are decomposed into permissions, whereas in a bottom-up approach, permissions are aggregated into roles. Pete Epstein, Ravi S. Sandhu |
ACSAC | 2 |
| 2001 | Secure Role-Based Workflow Models
Savith Kandala, Ravi S. Sandhu |
DBSec | 2 |
| 2001 | Role-based Access Control on the Web Using LDAP
Joon S. Park, Gail-Joon Ahn, Ravi S. Sandhu |
DBSec | 3 |
| 2001 | Panel: The next generation of acess control models (panel session): do we need them and what should they be?abstractResearch on access control models was started in the 1960s and 1970s by the two thrusts of mandatory and discretionary access control. Mandatory access control (MAC) came from the military and national security arenas whereas discretionary access control (DAC) had its roots in academic and commercial research laboratories. These two thrusts were dominant through the 1970s and 1980s almost to exclusion of any other approach to access control models. In the 1990s we have seen a dramatic shift towards pragmatism. The dominant access-control model of the 1990s is role-based access control (RBAC). It is now understood that RBAC encompasses MAC and DAC as special cases and goes beyond them in providing a policy-neutral framework. This SACMAT meeting has evolved from a highly successful and productive series of ACM workshops on RBAC. This panel will address the basic question of where do we go next with access control models. Do we need additional models or can we simply evolve the current set of RBAC models? Is RBAC fundamentally deficient in some way? Where should be go in terms of standards? Is there useful formal and theoretical work to be done in the access control models arena? The first meeting with the title SACMAT is a fitting place to address these questions. Ravi S. Sandhu, Elisa Bertino, Trent Jaeger, D. Richard Kuhn, Carl E. Landwehr |
SACMAT | 1 |
| 2001 | Decentralized user group assignment in Windows NT
Gail-Joon Ahn, Ravi S. Sandhu |
J. Syst. Softw. | 2 |
| 2001 | Proposed NIST standard for role-based access controlabstractIn this article we propose a standard for role-based access control (RBAC). Although RBAC models have received broad support as a generalized approach to access control, and are well recognized for their many advantages in performing large-scale authorization management, no single authoritative definition of RBAC exists today. This lack of a widely accepted model results in uncertainty and confusion about RBAC's utility and meaning. The standard proposed here seeks to resolve this situation by unifying ideas from a base of frequently referenced RBAC models, commercial products, and research prototypes. It is intended to serve as a foundation for product development, evaluation, and procurement specification. Although RBAC continues to evolve as users, researchers, and vendors gain experience with its application, we feel the features and components proposed in this standard represent a fundamental and stable set of mechanisms that may be enhanced by developers in further meeting the needs of their customers. As such, this document does not attempt to standardize RBAC features beyond those that have achieved acceptance in the commercial marketplace and research community, but instead focuses on defining a fundamental and stable set of RBAC components. This standard is organized into the RBAC Reference Model and the RBAC System and Administrative Functional Specification. The reference model defines the scope of features that comprise the standard and provides a consistent vocabulary in support of the specification. The RBAC System and Administrative Functional Specification defines functional requirements for administrative operations and queries for the creation, maintenance, and review of RBAC sets and relations, as well as for specifying system level functionality in support of session attribute management and an access control decision process. David F. Ferraiolo, Ravi S. Sandhu, Serban I. Gavrila, D. Richard Kuhn, Ramaswamy Chandramouli |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2001 | Role-based access control on the webabstractCurrent approaches to access control on the Web servers do not scale to enterprise-wide systems because they are mostly based on individual user identities. Hence we were motivated by the need to manage and enforce the strong and efficient RBAC access control technology in large-scale Web environments. To satisfy this requirement, we identify two different architectures for RBAC on the Web, called user-pull and server-pull . To demonstrate feasibility, we implement each architecture by integrating and extending well-known technologies such as cookies, X.509, SSL, and LDAP, providing compatibility with current web technologies. We describe the technologies we use to implement RBAC on the Web in different architectures. Based on our experience, we also compare the tradeoffs of the different approaches. Joon S. Park, Ravi S. Sandhu, Gail-Joon Ahn |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2000 | Framework for Role-based Delegation ModelsabstractThe basic idea behind delegation is that some active entity in a system delegates authority to another active entity to carry out some functions on behalf of the former. Delegation in computer systems can take many forms: human to human, human to machine, machine to machine, and perhaps even machine to human. We focuses on the human to human form of delegation using roles. As we show, there are many different ways in which role-based human-to-human delegation can occur. We develop a framework for identifying interesting cases that can be used for building role-based delegation models. This is accomplished by identifying the characteristics related to delegation, using these characteristics to generate possible delegation cases, and using a systematic approach to reduce the large number of cases into few useful cases which can be used to build delegation models. Ezedin Barka, Ravi S. Sandhu |
ACSAC | 2 |
| 2000 | Binding Identities and Attributes using Digitally Signed CertificatesabstractA certificate is digitally signed by a certificate authority (CA) to confirm that the information in the certificate is valid and belongs to the subject. Certificate users can verify the integrity and validity of a certificate by checking the issuing CA's digital signature in the certificate and, if necessary, chasing certificate chain and revocation lists. Usually, we use certificates to provide the integrity of identity or attribute information of the subject. Attributes must be coupled with the corresponding identities. We introduce comprehensive approaches to bind identity and attribute certificates, identifying three different techniques: monolithic, autonomic, and chained signatures. We describe each technique and analyze the relative advantages and disadvantages of each. Joon S. Park, Ravi S. Sandhu |
ACSAC | 2 |
| 2000 | Security Architectures for Controlled Digital Information DisseminationabstractBesides securing transmission of digital information at lower layers, several application-level security solutions for controlled dissemination of digital information have been developed using cryptographic, watermarking or use-control technologies. These dissemination control solutions have been designed for different business purposes. Little research, if any, identifies security architectures for controlling or tracking digital information dissemination in general. The identification of such will provide a foundation for developing appropriate security solutions for organizations' secure dissemination of digital information, and provide a better understanding of current application-level security solutions. We identify eight application-level security architectures based on the following three elements: virtual machine, control set and distribution style. Some of the architectures provide control and tracking capabilities for dissemination and usage of digital information, while others provide only tracking capability. We describe the architectures and compare their capabilities, merits and demerits. In addition, we review briefly some of the required mechanisms, including watermarking and use-control technologies. Also, we relate some of commercial solutions to our security architectures in order to provide insight on the current availability of our solutions architectures. Ravi S. Sandhu, J. Schifalacqua |
ACSAC | 2 |
| 2000 | Role-based authorization constraints specificationabstractConstraints are an important aspect of role-based access control (RBAC) and are often regarded as one of the principal motivations behind RBAC. Although the importance of contraints in RBAC has been recogni zed for a long time, they have not recieved much attention. In this article, we introduce an intuitive formal language for specifying role-based authorization constraints named RCL 2000 including its basic elements, syntax, and semantics. We give soundness and completeness proofs for RCL 2000 relative to a restricted form of first-order predicate logic. Also, we show how previously identified role-based authorization constraints such as separtation of duty (SOD) can be expressed in our language. Moreover, we show there are other significant SOD properties that have not been previously identified in the literature. Our work shows that there are many alternate formulations of even the simplest SOD properties, with varying degree of flexibility and assurance. Our language provides us a rigorous foundation for systematic study of role-based authorization constraints. Gail-Joon Ahn, Ravi S. Sandhu |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2000 | Configuring role-based access control to enforce mandatory and discretionary access control policiesabstractAccess control models have traditionally included mandatory access control (or lattice-based access control) and discretionary access control. Subsequently, role-based access control has been introduced, along with claims that its mechanisms are general enough to simulate the traditional methods. In this paper we provide systematic constructions for various common forms of both of the traditional access control paradigms using the role-based access control (RBAC) models of Sandhu et al., commonly called RBAC96. We see that all of the features of the RBAC96 model are required, and that although for the manatory access control simulation, only one administrative role needs to be assumed, for the discretionary access control simulations, a complex set of administrative roles is required. Sylvia L. Osborn, Ravi S. Sandhu, Qamar Munawer |
ACM Trans. Inf. Syst. Secur. | 2 |
| 1999 | Information Security Education for the Next Millennium: Building the Next Generation of Practitioners (Forum)
Ron Ross, Cynthia E. Irvine, Charles Reynolds, Ravi S. Sandhu, Blaine Burnham, Rayford B. Vaughn |
ACSAC | 4 |
| 1999 | The ARBAC99 Model for Administration of RolesabstractRole-Based Access Control (RBAC) is a flexible and policy-neutral access control technology. For large systems-with hundreds of roles, thousands of users and millions of permissions-managing roles, users, permissions and their interrelationships is a formidable task that cannot realistically be centralized an a small team of security administrators. An appealing possibility is to use RBAC itself to facilitate decentralized administration of RBAC. The ARBAC97 (administrative RBAC '97) model was recently introduced for this purpose. ARBAC97 has three sub-models called URA97 (for user-role administration), PRA97 (for permission-role administration) and RRA97 (for role-role administration). In this paper we define enhancements to ARBAC97 to give us the new ARBAC99 model. Specifically the URA and PRA sub-models of ARBAC99 introduce significant new features relative to their counterparts in ARBAC97 (while RRA is left unchanged). ARBAC99 incorporates the concept of mobile and immobile users and permissions for the first time in this arena. This paper gives a formal definition of ARBAC99, motivates these enhancements and analyzes several subtle issues that arise in this context. Ravi S. Sandhu, Qamar Munawer |
ACSAC | 1 |
| 1999 | Extending The BFA Workflow Authorization Model to Express Weighted Voting
Savith Kandala, Ravi S. Sandhu |
DBSec | 2 |
| 1999 | RBAC on the Web by Secure Cookies
Joon S. Park, Ravi S. Sandhu, SreeLatha Ghanta |
DBSec | 2 |
| 1999 | Role-based Administration of User-Role Assignment: The URA97 Model and its Oracle ImplementationabstractIn role-based access control (RBAC) permissions are associated with roles, and users are made members of appropriate roles thereby acquiring the roles’ permissions. The principal motivation behind RBAC is to simplify administration. An appealing poss Ravi S. Sandhu, Venkata Bhamidipati |
J. Comput. Secur. | 1 |
| 1999 | Towards role-based administration in network information services
Gail-Joon Ahn, Ravi S. Sandhu |
J. Netw. Comput. Appl. | 2 |
| 1999 | EditorialabstractNo abstract available. Ravi S. Sandhu |
ACM Trans. Inf. Syst. Secur. | 1 |
| 1999 | The ARBAC97 Model for Role-Based Administration of RolesabstractIn role-based access control (RBAC), permissions are associated with roles' and users are made members of roles, thereby acquiring the roles; permissions. RBAC's motivation is to simplify administration of authorizations. An appealing possibility is to use RBAC itself to manage RBAC, to further provide administrative convenience and scalability, especially in decentralizing administrative authority, responsibility, and chores. This paper describes the motivation, intuition, and formal definition of a new role-based model for RBAC administration. This model is called ARBAC97 (administrative RBAC '97) and has three components: URA97 (user-role assignment '97), RPA97 (permission-role assignment '97), and RRA97 (role-role assignment '97) dealing with different aspects of RBAC administration. URA97, PRA97, and an outline of RRA97 were defined in 1997, hence the designation given to the entire model. RRA97 was completed in 1998. ARBAC97 is described completely in this paper for the first time. We also discusses possible extensions of ARBAC97. Ravi S. Sandhu, Venkata Bhamidipati, Qamar Munawer |
ACM Trans. Inf. Syst. Secur. | 1 |
| 1998 | Concentric Supervision of Security Applications: A New Security Management ParadigmabstractThis paper questions the status quo regarding security management (SM) tools that function in an isolated, monolithic fashion. People work best by interacting with others and with their systems to see the "big picture" to interpret individual events. Our view of SM called concentric supervision of security applications (CSSA) is a continuous cycle of information flow. CSSA processing of status information and control of security features does not replace existing notions. It serves to enhance the existing ad hoc and segmented "engineered" solutions so that SM systems support "the way people work". We divide management functions into three phases: administration, operations, and assessment. Different skills, authority, and data are needed to perform tasks in each phase, but some information must flow for efficient and effective functionality. We give suggestions on some linkages by describing typical SM scenarios and how they might function. Parallels are drawn with related issues in network management systems and relationships to current management approaches are discussed. P. C. Hyland, Ravi S. Sandhu |
ACSAC | 2 |
| 1998 | The RRA97 Model for Role-Based Administration of Role HierarchiesabstractRole-based access control (RBAC) has recently received a lot of attention due to its flexibility, expressive power and simplicity in administration. In RBAC permissions are associated with roles and users are made members of roles thereby acquiring the associated permissions. Centralized management of RBAC in large systems is a tedious and costly task. An appealing possibility is to use RBAC itself to facilitate decentralized administration of RBAC. The recently proposed ARBAC97 (administrative RBAC '97) model identifies components called URA97, PRA97 and RRA97 for administration of user-role, permission-role and role-role assignments respectively. URA97 and PRA97 have already been described in detail in the literature, whereas RRA97 has so far not been defined. The central contribution of this paper is to give a complete and formal definition of RRA97, thereby completing the ARBAC97 model. The effect of role-role assignment is to construct a role hierarchy (that is, a partial order) in which senior roles inherit permissions from junior roles. Modifications to the role hierarchy can have drastic impact on the effective distribution of permissions to roles. At the same time we would like to decentralize this aspect of RBAC administration so that, for example, it should be possible for project security officers to rearrange roles within a project without impacting other role relationships within the department in which the project exists. RRA97 shows how this goal can be achieved. Ravi S. Sandhu, Qamar Munawer |
ACSAC | 1 |
| 1998 | EditorialabstractNo abstract available. Ravi S. Sandhu |
ACM Trans. Inf. Syst. Secur. | 1 |
| 1998 | The Multilevel Relational (MLR) Data ModelabstractMany multilevel relational models have been proposed; different models offer different advantages. In this paper, we adapt and refine several of the best ideas from previous models and add new ones to build the new Multilevel Relational (MLR) data model. MLR provides multilevel relations with element-level labeling as a natural extension of the traditional relational data model. MLR introduces several new concepts (notably, data-borrow integrity and the UPLEVEL statement) and significantly redefines existing concepts (polyinstantiation and referential integrity as well as data manipulation operations). A central contribution of this paper is proofs of soundness, completeness, and security of MLR. A new data-based semantics is given for the MLR data model by combining ideas from SeaView, belief-based semantics, and LDV. This new semantics has the advantages of both eliminating ambiguity and retaining upward information flow. MLR is secure, unambiguous, and powerful. It has five integrity properties and five operations for manipulating multilevel relations. Soundness, completeness, and security show that any of the five database manipulation operations will keep database states legal (i.e., satisfy all integrity properties), that every legal database state can be constructed, and that MLR is noninterfering. The expressive power of MLR also compares favorably with several other models. Ravi S. Sandhu |
ACM Trans. Inf. Syst. Secur. | 1 |
| 1997 | Lattice Based Models for Controlled Sharing of Confidential Information in the Saudi Hajj SystemabstractThe pilgrimage (Hajj) is an annual event that takes place in Saudi Arabia. Three major government ministries (Foreign, Internal, and Hajj) create and process Hajj data separately in their systems. Currently all data sharing between these ministries regarding Hajj is done manually. Benefits from sharing data electronically are obvious. But due to the sensitivity of some data and the common requirement of not sharing everything, a trusted environment which provides interoperability between these systems while ensuring confidentiality of shared data is needed. In order to study the possibility of establishing such an environment, data was collected regarding the security requirements of the three Saudi ministries directly from the source through interviews. There are three increasingly sophisticated security requirements: no obligation access security, multi level security, and Chinese Wall security. The paper analyzes each security requirement, builds a lattice model for it, and uses these models to specify the information flow policy for each system. T. F. Himdi, Ravi S. Sandhu |
ACSAC | 2 |
| 1997 | The URA97 Model for Role-Based User-Role Assignment
Ravi S. Sandhu, Venkata Bhamidipati |
DBSec | 1 |
| 1997 | Task-Based Authorization Controls (TBAC): A Family of Models for Active and Enterprise-Oriented Autorization Management
Roshan K. Thomas, Ravi S. Sandhu |
DBSec | 2 |
| 1997 | SNMP-based Network Security Management
P. C. Hyland, Ravi S. Sandhu |
Integrated Network Management | 2 |
| 1996 | Access Control: The Neglected Frontier
Ravi S. Sandhu |
ACISP | 1 |
| 1996 | Open Issues in Database Security
Ravi S. Sandhu, J. Campbell |
DBSec | 1 |
| 1996 | Implementation Experiences and Prospects
Ravi S. Sandhu, LouAnna Notargiacomo, Jesse C. Worthington |
DBSec | 1 |
| 1996 | Role Hierarchies and Constraints for Lattice-Based Access Controls
Ravi S. Sandhu |
ESORICS | 1 |
| 1996 | The Expressive Power of Multi-parent Creation in Monotonic Access Control ModelsabstractFormal demonstration of equivalence or nonequivalence of different security models helps identify the fundamental constructs and principles in such models. In this paper, we demonstrate the nonequivalence of two monotonic access control models that differ only in the creation operation for new subj ects and/or objects; in particular, we show that single-parent creation is less expressive than multi-parent creation. The nature of the proof indicates that this result will apply to any monotonic access control model. The nonequivalence proof is carried out on an abstract access control model, following which the results are interpreted in standard formulations. In particular, we apply the results to demonstrate nonequivalence of the Schematic Protection Model (SPM) and the Extended Schematic Protection Model (ESPM). We also show how the results apply to the typed access matrix model (TAM), which is an extension of the well known access matrix model formalized by Harrison, Ruzzo and Ullman (HRU). The results in this paper offer theoretical justification for regarding single-parent and multi-parent creation as fundamentally different operations in a monotonic context. The paper also demonstrates that in nonmonotonic models, multi-parent creation can be reduced to single-parent creation, thereby neutralizing the difference in expressive power. Paul Ammann, Richard J. Lipton, Ravi S. Sandhu |
J. Comput. Secur. | 3 |
| 1996 | A Trusted Subject Architecture for Multilevel Secure Object-Oriented DatabasesabstractWe address security in object-oriented database systems for multilevel secure environments. Such an environment consists of users cleared to various security levels, accessing information labeled with varying classifications. Our purpose is three-fold. First, we show how security can be naturally incorporated into the object model of computing so as to form a foundation for building multilevel secure object-oriented database management systems. Next, we show how such an abstract security model can be realized under a cost-effective, viable, and popular security architecture. Finally, we give security arguments based on trusted subjects and a formal proof to demonstrate the confidentiality of our architecture and approach. A notable feature of our solution is the support for secure synchronous write-up operations. This is useful when low level users want to send information to higher level users. In the object-oriented context, this is naturally modeled and efficiently accomplished through write-up messages sent by low level subjects. However, such write-up messages can pose confidentiality leaks (through timing and signaling channels) if the timing of the receipt and processing of the messages is observable to lower level senders. Such covert channels are a formidable obstacle in building high-assurance secure systems. Further, solutions to problems such as these have been known to involve various tradeoffs between confidentiality, integrity, and performance. We present a concurrent computation model that closes such channels while preserving the conflicting goals of confidentiality, integrity, and performance. Finally, we give a confidentiality proof for a trusted subject architecture and implementation and demonstrate that the trusted subject (process) cannot leak information in violation of multilevel security. Roshan K. Thomas, Ravi S. Sandhu |
IEEE Trans. Knowl. Data Eng. | 2 |
| 1995 | Panel Discussion: Role-Based Access Control and Next-Generation Security Models
Roshan K. Thomas, Elisa Bertino, Pierangela Samarati, Hans Hermann Brüggemann, Bret Hartman, Ravi S. Sandhu |
DBSec | 6 |
| 1995 | The semantics and expressive power of the MLR data modelabstractWe define the multilevel relational (MLR) data model for multilevel relations with element-level labeling. This model builds upon prior work of numerous authors in this area, and integrates ideas from a number of sources. A new data-based semantics is given to the MLR data model which combines ideas from SeaView, belief-based semantics and LDV model, and has the advantages of both eliminating ambiguity and retaining upward information flow. The resulting model is simple, unambiguous and powerful. It has five integrity properties and five operation statements for manipulating multilevel relations. In order to support this integration, we introduce several new concepts as well as redefine several old ones. The expressive power of the MLR model is also discussed in this paper, and is compared with several other models. We also address some issues in converting the MLR model to tuple-level labeling, including both scheme mapping and operation interpretation.> Ravi S. Sandhu |
S&P | 2 |
| 1994 | Role-based access control: a multi-dimensional viewabstractRecently there has been considerable interest in role-based access control (RBAC) as an alternative, and supplement, to the traditional discretionary and mandatory access controls (DAC and MAC) embodied in the Orange Book. The roots of RBAC can be traced back to the earliest access control systems. Roles have been used in a number of systems for segregating various aspects of security and system administration. Recent interest in RBAC has been motivated by the use of roles at the application level to control access to application data. This is an important innovation which offers the opportunity to realize benefits in securing an organization's information assets, similar to the benefits of employing databases instead of files as the data repository. A number of proposals for RBAC have been published in the literature, but there is no consensus on precisely what is meant by RBAC. This paper lays the groundwork for developing this consensus. In our view RBAC is a concept which has several dimensions, all of which may not be present in a given system or product. We envisage each dimension as being linearly ordered with respect to the sophistication of features provided. This leads us to the idea of a multi-dimension model for RBAC. Achieving agreement on what these dimensions are, and how the features in each dimension should be ordered, will take debate and time. Our contribution here is to lay out a vision on how to approach a common understanding of RBAC, and take a first cut at identifying the dimensions of RBAC. A major benefit of such a multidimensional RBAC would be to allow comparison of different products and assess their appropriateness for various system requirements.> Ravi S. Sandhu, Edward J. Coyne, Hal L. Feinstein, Charles E. Youman |
ACSAC | 1 |
| 1994 | One-Representative Safety Analysis in the Non-Monotonic Transform ModelabstractWe analyze the safety question for the Non-Monotonic Transform (NMT) model, an access control model that encompasses a wide variety of practical access control mechanisms. In general, safety analysis, i.e. whether it is possible for a specified subject to obtain a given access right for a certain object, is computationally intractable, even for many monotonic models. We identify one-representable NMT schemes and argue that they have tractable safety analysis. Safety analysis of one-representable schemes considers exactly one representative of each type of subject in the initial state, and thus the complexity of safety analysis is independent of the total number of subjects in the system. We demonstrate by example that one-representable schemes admit applications of practical interest, and that safety analysis guides the construction of such schemes.> Ravi S. Sandhu, Paul Ammann |
CSFW | 1 |
| 1994 | Conceptual Foundations for a Model of Task-based AuthorizationsabstractWe describe conceptual foundations to address integrity issues in computerized information systems from the enterprise perspective. The motivation for this effort stems from the recognition that existing models are formulated at too low a level of abstraction, to be useful for modeling organizational requirements, policy aspects, and internal controls, pertaining to maintenance of integrity in information systems. In particular, these models are primarily concerned with the integrity of internal data components within computer systems, and thus lack the constructs necessary to model enterprise level integrity principles. The starting point in the investigation is the notion of authorization functions and tasks associated with business activities carried out in the enterprise. These functions identify the authorization requirements while the authorization tasks embody the concepts required to carry out such authorizations. We believe a model of task-based authorizations will bridge the existing gap between low-level models and very high level ones looking at integrity from a purely organizational and sociological perspective devoid of any direct links to computerized systems. The work described is preliminary and conceptual in nature, but is a necessary prerequisite for the eventual development of a formal model.> Ravi S. Sandhu, Roshan K. Thomas |
CSFW | 1 |
| 1994 | On the Expressive Power of the Unary Transformation Model
Ravi S. Sandhu, Srinivas Ganta |
ESORICS | 1 |
| 1994 | Supporting Object-Based High-Assurance Write-up in Multilevel Databases for the Replicated Architecture
Roshan K. Thomas, Ravi S. Sandhu |
ESORICS | 2 |
| 1994 | On the minimality of testing for rights in transformation modelsabstractDefines and analyzes a family of access control models, called transformation models, which are based on the concept of transformation of rights. In these models, propagation of access rights is authorized entirely by existing rights for the object in question. Transformation models are useful for expressing various kinds of consistency, confidentiality, and integrity controls. These models also generalize the monotonic transform model of Sandhu, and its non-monotonic extension (NMT) by Sandhu and Suri. The authors argue that NMT is inadequate for expressing the document release example discussed by Sandhu and Suri, because it can test only one access matrix cell in its state changing commands. They then analyze the relative expressive power of testing two access matrix cells in state changing commands versus testing more than two. The conclusion is that it suffices to allow testing for two cells.> Ravi S. Sandhu, Srinivas Ganta |
S&P | 1 |
| 1993 | Expressive power of the single-object typed access matrix modelabstractThe single-object typed access matrix (SOTAM) model was recently introduced in the literature by Sandhu and Suri (1992). It is a special case of Sandhu's typed access matrix (TAM) model (1992). In SOTAM individual commands are restricted to modifying exactly one column of the access matrix (whereas individual TAM commands in general can modify multiple columns). Sandhu and Suri have outlined a simple implementation of SOTAM in a distributed environment using the familiar client-server architecture. In particular the stipulation that each-command modifies a single column of the access matrix, is reflected in the desirable property that each command modifies a single access control list corresponding to that column. In this paper we show that TAM and SOTAM are formally equivalent in their expressive power. This result establishes that SOTAM has precisely the same expressive power as TAM, while having a simple implementation at the same time. In a nutshell, this result tells us that manipulation of access control information can be achieved in its most general form by manipulation of a single access control list (ACL) at a time.> Ravi S. Sandhu, Srinivas Ganta |
ACSAC | 1 |
| 1993 | On Testing for Absence of Rights in Access Control ModelsabstractThe well-known access control model formalized by M.H. Harrison, W.C. Ruzzo, and J.D. Ullman (HRU) (1976), does not allow testing for absence of access rights in its commands. R.S. Sandhu's Typed Access Matrix (TAM) model (1992), which introduces strong typing into the HRU model, continues this tradition. P.E. Ammann R.S. Sandhu (1992), have proposed an extension of TAM called augmented TAM (ATAM), which allows testing for absence of rights. The motivation for ATAM is to express policies for dynamic separation of duties based on transaction control expressions. The authors study the question of whether or not testing for absence of access rights adds fundamental expressive power. They show that TAM and ATAM are formally equivalent in their expressive power. However, their construction indicates that while testing for absence of rights is theoretically unnecessary, such testing appears to be practically beneficial.> Ravi S. Sandhu, Srinivas Ganta |
CSFW | 1 |
| 1993 | On Five Definitions of Data Integrity
Ravi S. Sandhu |
DBSec | 1 |
| 1993 | Towards a Unified Framework and Theory for Reasoning about Security and Correctness of Transactions in Multilevel databases
Roshan K. Thomas, Ravi S. Sandhu |
DBSec | 2 |
| 1993 | Towards a task-based paradigm for flexible and adaptable access control in distributed applicationsabstractHistorically, the access control problem has been couched within the framework of subjects, object, and rights.In this paper we argue for a newer paradigm for distributed and multi-system applications, that transcends the subject-object view of access control.This new paradigm views access control and authorization not in terms of individual subjects and object, but rather in terms of long-lived tasks that need to be authorized and managed in information systems. Roshan K. Thomas, Ravi S. Sandhu |
NSPW | 2 |
| 1993 | Security for OODBMS (Or Systems) - PanelabstractNo abstract available. Ravi S. Sandhu |
OOPSLA | 1 |
| 1993 | A distributed capability-based architecture for the transform model
Ravi S. Sandhu, Gurpreet S. Suri |
Comput. Secur. | 1 |
| 1993 | A Kernelized Architecture for Multilevel Secure Object-Oriented Databases Supporting Write-UpabstractThis paper presents a kernelized architecture (i.e., an architecture in which no subject is exempted from the simple-security and ⋆-properties) for multilevel secure (mls) object-oriented database management systems (DBMS’s) which support write-up. R Roshan K. Thomas, Ravi S. Sandhu |
J. Comput. Secur. | 2 |
| 1992 | Implementing transaction control expressions by checking for absence of access rightsabstractSeparation of duties is an important, real-world requirement that access control models should support. The transaction control expression (TCE) for specifying dynamic separation of duties was previously introduced. The implementation of TCEs in the typed access matrix model (TAM) is considered. It is shown that TAM requires extension for satisfactory handling of dynamic separation of duties. In particular, dynamic separation requires the capability to explicitly test for the absence of rights in cells of the access matrix. It is illustrated how TAM, extended to incorporate such tests, can implement TCEs. The impact of checks for absence of rights on safety analysis is discussed (i.e. the determination of whether or not a given subject can acquire a given right to a given object).> Paul Ammann, Ravi S. Sandhu |
ACSAC | 2 |
| 1992 | The Expressive Power of Multi-Parent Creation in a Monotonic Access Control ModelabstractFormal demonstration of equivalence or nonequivalence of different security models helps identify the fundamental constructs and principles in such models. The authors demonstrate the nonequivalence of two monotonic access control models that differ only in the creation operation for new subjects and/or objects; in particular, they show that single-parent creation is less expressive than multi-parent creation in monotonic models. The paper also demonstrates that in nonmonotonic models, multi-parent creation can be reduced to single-parent creation, thereby neutralizing the difference in expressive power. The nonequivalence proof is carried out on an abstract access control model, following which the results are interpreted in standard formulations. In particular, they apply the results to demonstrate nonequivalence of the schematic protection model (SPM) and the extended schematic protection model (ESPM). They also show how the results apply to the typed access matrix model (TAM).> Paul Ammann, Richard J. Lipton, Ravi S. Sandhu |
CSFW | 3 |
| 1992 | Polyinstantation for Cover Stories
Ravi S. Sandhu, Sushil Jajodia |
ESORICS | 1 |
| 1992 | The typed access matrix modelabstractThe typed access matrix (TAM) model is defined by introducing the notion of strong typing into the Harrison, Ruzzo, and Ullman model (HRU) (M. H. Harrison et al., 1978). It is shown that monotonic TAM (MTAM) has decidable, but NP-hard, safety for its acyclic creation cases. It is further shown that ternary MTAM has polynomial time safety analysis for its acyclic cases, even though it is, in general, equivalent to MTAM. Ternary MTAM thus has strong safety properties. The expressive power of ternary MTAM has been shown to be equivalent to MTAM in general. The results establish that strong typing is crucial to achieving a useful demarcation between decidable and undecidable safety, and ternary monotonic commands are critical for tractable safety analysis.> Ravi S. Sandhu |
S&P | 1 |
| 1992 | Non-monotonic transformation of access rightsabstractIt is known that monotonic transformations unify a number of diverse access control mechanisms such as amplification, copy flags, separation of duties, and synergistic authorization. The importance and expressive power of nonmonotonic transformations is demonstrated. A formal model, called nonmonotonic transform (NMT), is defined. A distributed implementation of NMT is proposed using a client-server architecture. The implementation is remarkably simple and modular in concept. It is based on access control lists and allows for efficient and immediate revocation which could be partial, complete, selective, temporary, or permanent.> Ravi S. Sandhu, Gurpreet S. Suri |
S&P | 1 |
| 1992 | Lattice-based enforcement of Chinese Walls
Ravi S. Sandhu |
Comput. Secur. | 1 |
| 1992 | Eliminating polyinstantiation securely
Ravi S. Sandhu, Sushil Jajodia |
Comput. Secur. | 1 |
| 1992 | The Extended Schematic Protection ModelabstractAccess control models provide a formalism and framework for specifying control over access to information and other resources in multi-user computer systems. Useful access control models must balance expressive power with the decidability and complex Paul Ammann, Ravi S. Sandhu |
J. Comput. Secur. | 2 |
| 1992 | Expressive Power of the Schematic Protection ModelabstractIn this paper we show that the Schematic Protection Model (SPM) subsumes several well-known protection models as particular instances. We show this for a diverse collection of models including the Bell-LaPadula multilevel security model, take-grant m Ravi S. Sandhu |
J. Comput. Secur. | 1 |
| 1992 | Undecidability of Safety for the Schematic Protection Model with Cyclic Creates
Ravi S. Sandhu |
J. Comput. Syst. Sci. | 1 |
| 1991 | A distributed implementation of the extended schematic protection modelabstractProtection models provide a formalism for specifying control over access to information and other resources in a multi-user computer system. One such model, the extended schematic protection model (ESPM) has expressive power equivalent to the monotonic access matrix model of Harrison, Ruzzo, and Ullman (1976). Yet ESPM retains tractable safety analysis for many cases of practical interest. Thus ESPM is a very general model, and it is of interest whether ESPM can be implemented in a reasonable manner. The authors outline a distributed implementation for ESPM. The implementation is capability-based, with an architecture where servers act as mediators to all subject and object access. Capabilities are made nontransferable by burying the identity of subjects in them, and unforgeable by using a public key encryption algorithm. Timestamps and public keys are used as mechanisms for revocation.> Paul Ammann, Ravi S. Sandhu, Gurpreet S. Suri |
ACSAC | 2 |
| 1991 | A single-level scheduler for the replicated architecture for multilevel-secure databasesabstractThe replicated architecture for multilevel secure database systems provides security by replicating data into separate untrusted single-level database systems. To be successful, a system using the replicated architecture must have a concurrency and replica control algorithm that does not introduce any covert channels. Jajodia and Kogan (1990) have developed one such algorithm that uses update projections and a write-all replica control algorithm. The authors describe an alternative algorithm. The new algorithm uses replicated transactions and a set of queues organized according to security class. A new definition of correctness is required for this approach, so they present one and use it to show that the algorithm is correct. The existence of this new algorithm increases the viability of the replicated architecture as an alternative to kernelized approaches.> John P. McDermott, Sushil Jajodia, Ravi S. Sandhu |
ACSAC | 3 |
| 1991 | A Secure Kernelized Architecture for Multiple Object-Oriented DatabasesabstractThe authors present a secure kernelized architecture for multilevel object-oriented database management systems. The architecture is based on the notion of a message filter. It builds upon the typical architecture of current object-oriented database management systems. Since the operations mediated by the message filter are arbitrarily complex operations (as opposed to primitive reads and writes), a secure message filter requires careful attention to potential timing covert channels. Although the overall computation is logically a sequential one, to be secure one must actually execute pieces of the computation concurrently. This raises a synchronization problem for which they give a secure multiversion protocol. The fundamental problem solved is how to securely and correctly 'write up' in terms of abstract operations.> Ravi S. Sandhu, Roshan K. Thomas, Sushil Jajodia |
CSFW | 1 |
| 1991 | Towards a Multilevel Secure Relational Data ModelabstractAlthough there are several efforts underway to build multilevel secure relational database management systems, there is no clear consensus regarding what a multilevel secure relational data model exactly is. In part this lack of consensus on fundamental issues reflects the subtleties involved in extending the classical (single-level) relational model to a multilevel environment. Our aim in this paper is to discuss the most fundamental aspects of the multilevel secure relational model. Specifically, we consider two requirements: entity integrity and update semantics. Our overall goal is to preserve as much as possible the simplicity and flexibility of the relational model without sacrificing security in the process. 1 INTRODUCTION A large number of databases in the Department of Defense, the intelligence community and civilian government agencies contain data that are classified to have different security levels. All database users are also assigned security clearances. It is the respo... Sushil Jajodia, Ravi S. Sandhu |
SIGMOD Conference | 2 |
| 1991 | Safety Analysis for the Extended Schematic Protection ModelabstractIt is argued that the access matrix model of M.H. Harrison, W.L. Ruzzo and J.D. Ullman (HRU) (1976) has extremely weak safety properties; safety analysis is undecidable for most policies of practical interest. An alternate formulation of the HRU model is presented that gives strong safety properties. This alternative formulation is called the extended schematic protection model (ESPM). ESPM is derived from the schematic protection model (SPM) by extending the creation operation to allow multiple parents for a child, as opposed to the conventional create operation of SPM, which has a single parent for a child. It is shown that, despite its equivalence to HRU, ESPM, retains a tractable safety analysis for a large class of protection schemes that are of practical interest.> Paul Ammann, Ravi S. Sandhu |
S&P | 2 |
| 1991 | A Novel Decomposition of Multilevel Relations into Single-Level RelationsabstractPresents a novel decomposition algorithm that breaks a multilevel relation into single-level relations and a novel recovery algorithm which reconstructs the original multilevel relation from the decomposed single-level relations. There are several novel aspects to these decomposition and recovery algorithms which provide substantial advantages over previous proposals. The algorithms are formulated in the context of an operational semantics for multilevel relations, defined here by generalizing the usual update operations of structured query language (SQL) to multilevel relations. The algorithms, with minor modifications, can easily accommodate alternative update semantics which have been proposed in the literature. The algorithms are efficient because recovery is based solely on union-like operations without any use of joins. The decomposition is intuitively and theoretically simple, giving a sound basis for correctness.> Sushil Jajodia, Ravi S. Sandhu |
S&P | 2 |
| 1991 | Integrity principles and mechanisms in database management systems
Ravi S. Sandhu, Sushil Jajodia |
Comput. Secur. | 1 |
| 1990 | Extending the creation operation in the Schematic Protection ModelabstractProtection models provide a formalism for specifying control over access to information and other resources in a multi-user computer system. Useful protection models must balance expressive power with the complexity of safety analysis i.e. the determination of whether or not a given subject can ever acquire access to a given resource. The authors argue that, in terms of expressive power, a joint creation operation is a natural candidate for inclusion in an access control model, particularly in the context of integrity considerations. They extend the Schematic Protection Model (SPM) to allow for groups of subjects to jointly create other subjects and objects. They discuss the safety properties of ESPM. Despite the increase in expressive power, ESPM retains tractable safety analysis for many cases of practical interest.> Paul Ammann, Ravi S. Sandhu |
ACSAC | 2 |
| 1990 | Update semantics for multilevel relationsabstractA formal operational semantics is given for update operations on multilevel relations, i.e., relations in which individual data elements are classified at different levels. For this purpose, the familiar INSERT, UPDATE and DELETE operations of SQL are suitably generalized to cope with polyinstantiation. The authors conjecture that these operations are consistent (or sound) in that all relations which can be constructed will satisfy the basic integrity properties required of multilevel relations. They also conjecture that the operations are complete in that every multilevel relation can be constructed by some sequence of these operations.> Sushil Jajodia, Ravi S. Sandhu, Edgar H. Sibley |
ACSAC | 2 |
| 1990 | A Formal Framework for Single Level Decomposition of Multilevel RelationsabstractMultilevel relations in which security classifications are assigned at the granularity of individual data elements are considered. Usually these multilevel relations exist only at the logical level. In reality, a multilevel relation is decomposed into a collection of single level base relations which are then physically stored in a database, and a recovery algorithm is used to reconstruct the original multilevel relation. The authors formalize the relationship that exists between the decomposition-independent filtered relations and the multilevel relations obtained from decomposed single level relations using the recovery algorithm. Three requirements that must be met by any decomposition and recovery algorithms are stated. It is pointed out that previous algorithms given by the authors (1990) meet these requirements.> Sushil Jajodia, Ravi S. Sandhu |
CSFW | 2 |
| 1990 | A New Polyinstantiation Integrity Constraint for Multilevel RelationsabstractA new polyinstantiation integrity constraint for multilevel relations based on the intuitive idea that every entity in a relation can have at most one tuple for every access class is proposed. The consequences of this property and some of its variations are discussed. A core set of properties which should apply to all relations is identified. These are entity integrity, interinstance integrity, subsumption integrity, and polyinstantiation integrity in the sense of PI-FD. Specific models impose additional polyinstantiation constraints. Oakland requires PI-null, Sea View requires PI-MVD, and the new Franconia model requires PI-Tuple-class. Each of these properties appears likely to arise often enough in practice to justify DBMS (database management system) support for its enforcement on a relation-by-relation basis.> Ravi S. Sandhu, Sushil Jajodia, Teresa F. Lunt |
CSFW | 1 |
| 1990 | Polyinstantiation Integrity in Multilevel RelationsabstractPolyinstantiation integrity (PI) as defined in the Sea View multilevel relational data model consists of a functional dependency component and a multivalued dependency component. It is shown that the latter component rules out many practically useful relations and is therefore unduly restrictive. This leads the authors to propose that PI be defined to consist only of the functional dependency component. For this revised definition of PI, they formulate and prove correct a lossless decomposition of multilevel relations into single-level ones with recovery based on the natural join operation.> Sushil Jajodia, Ravi S. Sandhu |
S&P | 2 |
| 1989 | A perspective on integrity mechanismsabstractAccepting the common viewpoint that integrity is concerned with information modification rather than information disclosure or information availability, the author considers two views on what nondiscretionary controls are needed for information integrity: (1) Clark and Wilson's view that some separate mechanisms are required for enforcement of integrity policies, disjoint from those of the Orange Book (TCSEC), and (2) Gasser's view that techniques to protect against information modifications are almost always the same as (or a subset of) techniques to protect against information disclosure. The author agrees with the Clark-Wilson view, in which integrity requires nondiscretionary access-control mechanisms other than label-based mandatory controls. He lists his objections to Gasser's view.> Ravi S. Sandhu |
ACSAC | 1 |
| 1989 | Transformation of Access RightsabstractThe author introduces the concept of transformation of access rights to unify a variety of access-control mechanisms. These mechanisms have mostly been proposed independently of each other to deal with various integrity issues. Their common foundation is abstracted in a model called transform. The formalization makes it possible to investigate the minimal features required to support transform. The relation of transform to existing access-control models is then considered. It is shown that the access-matrix model transform is outside the class of systems for which safety is known to be decidable. On the other hand it is shown that transform is an instance of the decidable cases of the schematic protection model.> Ravi S. Sandhu |
S&P | 1 |
| 1989 | The Reflected Tree Hierarchy for Protection and Sharing
Ravi S. Sandhu |
Inf. Process. Lett. | 1 |
| 1989 | The Demand Operation in the Schematic Protection Model
Ravi S. Sandhu |
Inf. Process. Lett. | 1 |
| 1989 | Recognizing Immediacy in an N-Tree Hierarchy and Its Application to Protection GroupsabstractThe benefits of providing access control with groups of users as the unit of granularity are enhanced if the groups are organized in a hierarchy (partial order) by the subgroup relation> Ravi S. Sandhu |
IEEE Trans. Software Eng. | 1 |
| 1988 | Expressive Power of the Schematic Protection Model
Ravi S. Sandhu |
CSFW | 1 |
| 1988 | Nested categories for access control
Ravi S. Sandhu |
Comput. Secur. | 1 |
| 1988 | Cryptographic Implementation of a Tree Hierarchy for Access Control
Ravi S. Sandhu |
Inf. Process. Lett. | 1 |
| 1988 | The schematic protection model: its definition and analysis for acyclic attenuating schemesabstractThe protection state of a system is defined by the privileges possessed by subjects at a given moment. Operations that change this state are themselves authorized by the current state. This poses a design problem in constructing the initial state so that all derivable states conform to a particular policy. It also raises an analysis problem of characterizing the protection states derivable from a given initial state. A protection model provides a framework for both design and analysis. Design generality and tractable analysis are inherently conflicting goals. Analysis is particularly difficult if creation of subjects is permitted. The schematic protection model resolves this conflict by classifying subjects and objects into protection types. The privileges possessed by a subject consist of a type-determined part specified by a static protection scheme and a dynamic part consisting of tickets (capabilities). It is shown that analysis is tractable for this model provided certain restrictions are imposed on subject creation. A scheme authorizes creation of subjects via a binary relation on subject types. Our principal constraint is that this relation be acyclic, excepting loops that authorize a subject to create subjects of its own type. Our assumptions admit a variety of useful systems. Ravi S. Sandhu |
J. ACM | 1 |
| 1988 | The NTree: A Two Dimension Partial Order for Protection GroupsabstractThe benefits of providing access control with groups of users rather than with individuals as the unit of granularity are well known. These benefits are enhanced if the groups are organized in a subgroup partial order. A class of such partial orders, called ntrees, is defined by using a forest of rooted trees or inverted rooted trees as basic partial orders and combining these by refinement. Refinement explodes an existing group into a partially ordered ntree of new groups while maintaining the same relationship between each new group and the nonexploded groups that the exploded group had. Examples are discussed to show the practical significance of ntrees and the refinement operation. It is shown that ntrees can be represented by assigning a pair of integers called lr-values to each group so that g is a subgroup of h if and only if l[g] ≤ l[h] and r[g] ≤ r[h]. Refinement allows a complex ntree to be developed incrementally in a top-down manner and is useful for the initial definition of an ntree as well as for subsequent modifications. To make the latter use of refinement practical, a method is presented for assigning lr-values to the new groups introduced by refinement so lr-values assigned to nonexploded groups need not be changed. It is also shown how to guarantee that the lr-values of the exploded group will get assigned to one of the new groups. Ravi S. Sandhu |
ACM Trans. Comput. Syst. | 1 |
| 1986 | Some Owner Based Schemes with Dynamic Groups in the Schematic Protection ModelabstractThe discretionary ability implied in the notion of ownership is often provided in terms of groups rather than individuals. The group approach has its conveniences but is limiting since access decisions do not discriminate among members of a group. The ability for users to define group membership dynamically offers flexibility and convenience. In this paper we investigate a variety of polices for doing so in the context of a simplified file system. We specify the polices using the Schematic Protection Model (SPM). Our investigation reveals that there are many policy options and demonstrates how SPM is used to precisely specify these options. Ravi S. Sandhu, M. E. Share |
S&P | 1 |
| 1985 | Analysis of Acyclic Attenuating Systems for the SSR Protection ModelabstractThe distribution of privileges in domains of subjects defines the protection state of a system. Operations which change this state are themselves authorized by privileges in the current state. This poses an analysis problem of characterizing states which are derivable from a given initial state. Analysis is particularly difficult if creation of new subjects is permitted. Also the need for tractable analysis conflicts with the need for generality in specifying policies. The Schematic Send-Receive (SSR) model resolves this conflict by classifying subjects and objects into protection types. The domain of each subject consists of a static type-determined part specified by an authorization scheme and a dynamic part consisting of tickets (capabilities). We analyze a restricted class of systems in SSR. Specifically, the scheme authorizes crest ion via a binary relation on types. Our major constraint is that this relation be acyclic excepting loops which authorize a subject to create subjects of its own type. Our constraints admit a large class of useful systems. Ravi S. Sandhu |
S&P | 1 |