A Graph-Based Formal Access Control Model to Support Positive & Negative Permissions, Exceptions, Redundancy & Conflict Detection, Permission to Delegate, Delegation, Separation of Duties (SoD), and SoD Exceptions & Violation Detection
dc.contributor.advisor | De Leon, Daniel Conte | |
dc.contributor.author | Alkhorem, Azan Hamad | |
dc.date.accessioned | 2024-05-26T12:07:05Z | |
dc.date.available | 2024-05-26T12:07:05Z | |
dc.date.issued | 2024-12-30 | |
dc.description.abstract | Access control policies models provide a better approach to control users actives regarding allowing or denying such action to user or group within the resources. This mechanism allowed us to verify the grant or the denial of access. Within the access control hierarchy structure, there are more features that must be supported with different permissions on non-hierarchy and hierarchy structure. In this study we developed a methodology that supports the enhancement of positive policy represented by (YES) and adds negative policy represented by (NO). Moreover, we include supporting both types of permission to delegate and both types of delegation. Although, we implement supporting an exception policies approach for both types of stander policies positive and negative. Furthermore, we developed a method to adopt two different types of Separation of Duties (SoD). This includes redundancy, conflict detection, valid polices request of SoD, violation, and non-violation polices request between each type itself and between the first type against the second concept of SoD rules as well as vice versa. In addition, we validate another technique that these two different types of SoD do not violate both types of stander policies concept. Finally, we examine both types of stander policies concept never violate both types of SoD rules in the hierarchy manner. These challenges have been successfully verified on the hierarchy policy model (HPol). These features give the HPol model more advantages supporting complex polices on non-hierarchy and hierarchy structure. | |
dc.format.extent | 337 | |
dc.identifier.uri | https://hdl.handle.net/20.500.14154/72146 | |
dc.language.iso | en_US | |
dc.publisher | University of Idaho | |
dc.subject | Access Control | |
dc.subject | Cybersecurity | |
dc.subject | Delegation | |
dc.subject | Policy Exceptions | |
dc.subject | Redundancy and Conflict Detection | |
dc.subject | Separation of Duties | |
dc.title | A Graph-Based Formal Access Control Model to Support Positive & Negative Permissions, Exceptions, Redundancy & Conflict Detection, Permission to Delegate, Delegation, Separation of Duties (SoD), and SoD Exceptions & Violation Detection | |
dc.type | Thesis | |
sdl.degree.department | Computer Science | |
sdl.degree.discipline | Cyber Security | |
sdl.degree.grantor | University of Idaho | |
sdl.degree.name | Doctor of Philosophy |