Skip to main content

Distributed proving in access-control systems

Publication ,  Conference
Bauer, L; Garriss, S; Reiter, MK
Published in: Proceedings - IEEE Symposium on Security and Privacy
November 10, 2005

We present a distributed algorithm for assembling a proof that a request satisfies an access-control policy expressed in a formal logic, in the tradition of Lampson et al. [16]. We show analytically that our distributed proof-generation algorithm succeeds in assembling a proof whenever a centralized prover utilizing remote certificate retrieval would do so. In addition, we show empirically that our algorithm outperforms centralized approaches in various measures of performance and usability, notably the number of remote requests and the number of user interruptions. We show that when combined with additional optimizations including caching and automatic tactic generation, which we introduce here, our algorithm retains its advantage, while achieving practical performance. Finally, we briefly describe the utilization of these algorithms as the basis for an access-control framework being deployed for use at our institution. © 2005 IEEE.

Duke Scholars

Published In

Proceedings - IEEE Symposium on Security and Privacy

DOI

ISSN

1081-6011

Publication Date

November 10, 2005

Start / End Page

81 / 95
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Bauer, L., Garriss, S., & Reiter, M. K. (2005). Distributed proving in access-control systems. In Proceedings - IEEE Symposium on Security and Privacy (pp. 81–95). https://doi.org/10.1109/SP.2005.9
Bauer, L., S. Garriss, and M. K. Reiter. “Distributed proving in access-control systems.” In Proceedings - IEEE Symposium on Security and Privacy, 81–95, 2005. https://doi.org/10.1109/SP.2005.9.
Bauer L, Garriss S, Reiter MK. Distributed proving in access-control systems. In: Proceedings - IEEE Symposium on Security and Privacy. 2005. p. 81–95.
Bauer, L., et al. “Distributed proving in access-control systems.” Proceedings - IEEE Symposium on Security and Privacy, 2005, pp. 81–95. Scopus, doi:10.1109/SP.2005.9.
Bauer L, Garriss S, Reiter MK. Distributed proving in access-control systems. Proceedings - IEEE Symposium on Security and Privacy. 2005. p. 81–95.

Published In

Proceedings - IEEE Symposium on Security and Privacy

DOI

ISSN

1081-6011

Publication Date

November 10, 2005

Start / End Page

81 / 95