ReBAC2015: Interoperability of Relationship- and Role-Based Access Control
atmire.migration.oldid | 3554 | |
dc.contributor.advisor | Fong, Philip | |
dc.contributor.author | Rizvi, Syed Zain | |
dc.date.accessioned | 2015-09-16T22:14:58Z | |
dc.date.embargolift | 2016-09-15T22:14:58Z | |
dc.date.issued | 2015-09-16 | |
dc.date.submitted | 2015 | en |
dc.description.abstract | Relationship-Based Access Control (ReBAC) is a general-purpose access control paradigm for application domains in which authorization must take into account the relationship between the access requestor and the resource owner. This thesis presents an evolution of Fong's ReBAC model in two steps. First, I formalize and extend the first time implementation of ReBAC into a production-scale medical records system, OpenMRS. This extension incorporates sophisticated authorization schemes recently proposed in the literature, as well as a performance evaluation of these schemes. Second, the model is further extended to incorporate the notion of demarcations and authorization-time constraints. These extensions allow ReBAC to interoperate with legacy Role-Based Access Control at a fine-grained level, and significantly increase the expressiveness of the model. Also presented are the design of two authorization procedures (one of which has an algorithmic structure akin to an SMT solver) along with optimization techniques. | en_US |
dc.description.embargoterms | 12 months | en_US |
dc.identifier.citation | Rizvi, S. Z. (2015). ReBAC2015: Interoperability of Relationship- and Role-Based Access Control (Master's thesis, University of Calgary, Calgary, Canada). Retrieved from https://prism.ucalgary.ca. doi:10.11575/PRISM/27553 | en_US |
dc.identifier.doi | http://dx.doi.org/10.11575/PRISM/27553 | |
dc.identifier.uri | http://hdl.handle.net/11023/2459 | |
dc.language.iso | eng | |
dc.publisher.faculty | Graduate Studies | |
dc.publisher.institution | University of Calgary | en |
dc.publisher.place | Calgary | en |
dc.rights | University of Calgary graduate students retain copyright ownership and moral rights for their thesis. You may use this material in any way that is permitted by the Copyright Act or through licensing that has been assigned to the document. For uses that are not allowable under copyright legislation or licensing, you are required to seek permission. | |
dc.subject | Computer Science | |
dc.subject.classification | Access Control | en_US |
dc.subject.classification | relationship predicate | en_US |
dc.subject.classification | protection state | en_US |
dc.subject.classification | access control model | en_US |
dc.subject.classification | authorization principal | en_US |
dc.subject.classification | relationship based access control | en_US |
dc.subject.classification | authorization procedure | en_US |
dc.subject.classification | lazy evaluation | en_US |
dc.subject.classification | role based access control | en_US |
dc.subject.classification | demarcation hierarchy | en_US |
dc.subject.classification | lazy authorization procedure | en_US |
dc.subject.classification | authorization graph | en_US |
dc.subject.classification | papr constraint | en_US |
dc.subject.classification | strict grant semantic | en_US |
dc.subject.classification | hybrid logic formula | en_US |
dc.subject.classification | hybrid logic | en_US |
dc.subject.classification | rebac model | en_US |
dc.subject.classification | eager evaluation | en_US |
dc.subject.classification | meap constraint | en_US |
dc.subject.classification | predicate value caching | en_US |
dc.subject.classification | privilege requirement | en_US |
dc.subject.classification | Language Policy | en_US |
dc.subject.classification | authorization decision | en_US |
dc.subject.classification | model checking | en_US |
dc.subject.classification | open source medical record system | en_US |
dc.subject.classification | access control policy | en_US |
dc.subject.classification | Social Network | en_US |
dc.subject.classification | ReBAC2015 | en_US |
dc.title | ReBAC2015: Interoperability of Relationship- and Role-Based Access Control | |
dc.type | master thesis | |
thesis.degree.discipline | Computer Science | |
thesis.degree.grantor | University of Calgary | |
thesis.degree.name | Master of Science (MSc) | |
ucalgary.item.requestcopy | true |
Files
License bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- license.txt
- Size:
- 2.65 KB
- Format:
- Item-specific license agreed upon to submission
- Description: