Cedar: A New Language for Expressive, Fast, Safe, and Analyzable Authorization
Joseph W. Cutler, Craig Disselkoen, Aaron Eline, Shaobo He, Kyle Headley, Michael Hicks, Kesha Hietala, Eleftherios Ioannidis, John H. Kastner, Anwar Mamat, Darin McAdams, Matt McCutchen
摘要
Cedar is a new authorization policy language designed to be ergonomic, fast, safe, and analyzable. Rather than embed authorization logic in an application’s code, developers can write that logic as Cedar policies and delegate access decisions to Cedar’s evaluation engine. Cedar’s simple and intuitive syntax supports common authorization use-cases with readable policies, naturally leveraging concepts from role-based, attribute-based, and relation-based access control models. Cedar’s policy structure enables access requests to be decided quickly. Cedar’s policy validator leverages optional typing to help policy writers avoid mistakes, but not get in their way. Cedar’s design has been finely balanced to allow for a sound and complete logical encoding, which enables precise policy analysis, e.g., to ensure that when refactoring a set of policies, the authorized permissions do not change. We have modeled Cedar in the Lean programming language, and used Lean’s proof assistant to prove important properties of Cedar’s design. We have implemented Cedar in Rust, and released it open-source. Comparing Cedar to two open-source languages, OpenFGA and Rego, we find (subjectively) that Cedar has equally or more readable policies, but (objectively) performs far better.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- VERINA: Benchmarking Verifiable Code GenerationZhe Ye, Zhengxu Yan, Jingxuan He, Timothe Kasriel 等ICLR 2026 · 被引用 34 次
- ROSpec: A Domain-Specific Language for ROS-Based Robot SoftwarePaulo Canelas, Bradley R. Schmerl, Alcides Fonseca, Christopher Steven TimperleyOOPSLA 2025 · 被引用 2 次
- Topaz: Declarative and Verifiable Authoritative DNS at CDN-ScaleJames Larisch, Timothy Alberdingk Thijm, Suleman Ahmad, Peter Wu 等SIGCOMM 2024 · 被引用 1 次
- Formally Verified Cloud-Scale AuthorizationAleks Chakarov, Jaco Geldenhuys, Matthew Heck, Michael Hicks 等ICSE 2025 · 被引用 1 次
- Accelerating Automated Program Verifiers by Automatic Proof LocalizationKiran Gopinathan, Dionysios Spiliopoulos, Vikram Goyal, Peter Müller 等CAV 2025 · 被引用 1 次
它引用的顶会 Paper2
相关 Paper
- Probabilistic Access Policies with Automated Reasoning SupportShaowei Zhu, Yunbo ZhangCAV 2024 · 被引用 1 次
- The Next 700 Policy Miners: A Universal Method for Building Policy MinersCarlos Cotrini, Luca Corinzia, Thilo Weghorn, David A. BasinCCS 2019 · 被引用 19 次
- Relia: Accelerating the Analysis of Cloud Access Control PoliciesDan Wang, Peng Zhang, Zhenrong Gu, Weibo Lin 等ASE 2025
- Automatically Reducing Privilege for Access Control PoliciesLoris D'Antoni, Shuo Ding, Amit Goel, Mathangi Ramesh 等OOPSLA 2024 · 被引用 11 次
- Block public access: trust safety verification of access control policiesMalik Bouchet, Byron Cook, Bryant Cutler, Anna Druzkina 等FSE 2020 · 被引用 25 次
