Probabilistic Access Policies with Automated Reasoning Support
Shaowei Zhu, Yunbo Zhang
摘要
Abstract Existing access policy languages like Cedar equipped with SMT-based automated reasoning capabilities are effective in providing formal guarantees about the policies. However, this scheme only supports access control based on deterministic information. Observing that certain information useful for access control can be described by random variables, we are motivated to develop a new paradigm of access control in which access policies contain rules about uncertainty, or more precisely, probabilities of random events. To compute these probabilities, we rely on probabilistic programming languages. Additionally, we show that the probabilistic part of these policies can be encoded in linear real arithmetic, which enables practical automated reasoning tasks such as proving relative permissiveness between policies. We demonstrate the advantages of the proposed probabilistic policies over the existing paradigm through two case studies on real-world datasets with a prototype implementation.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Cedar: A New Language for Expressive, Fast, Safe, and Analyzable AuthorizationJoseph W. Cutler, Craig Disselkoen, Aaron Eline, Shaobo He 等OOPSLA 2024 · 被引用 28 次
- Weighted programming: a programming paradigm for specifying mathematical modelsKevin Batz, Adrian Gallus, Benjamin Lucien Kaminski, Joost-Pieter Katoen 等OOPSLA 2022 · 被引用 18 次
- λPSI: exact inference for higher-order probabilistic programsTimon Gehr, Samuel Steffen, Martin T. VechevPLDI 2020 · 被引用 29 次
- Reactive probabilistic programmingGuillaume Baudart, Louis Mandel, Eric Atkinson, Benjamin Sherman 等PLDI 2020 · 被引用 1 次
- Synthesis of Probabilistic Privacy EnforcementMartin Kucera, Petar Tsankov, Timon Gehr, Marco Guarnieri 等CCS 2017 · 被引用 21 次
