{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:28:10Z","timestamp":1750307290419,"version":"3.41.0"},"reference-count":39,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2011,5,1]],"date-time":"2011-05-01T00:00:00Z","timestamp":1304208000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["244901"],"award-info":[{"award-number":["244901"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2011,5]]},"abstract":"<jats:p>\n            Access control to IT systems increasingly relies on the ability to compose policies. Hence there is benefit in any framework for policy composition that is intuitive, formal (and so \u201canalyzable\u201d and \u201cimplementable\u201d), expressive, independent of specific application domains, and yet able to be extended to create domain-specific instances. Here we develop such a framework based on Belnap logic. An access-control policy is interpreted as a\n            <jats:italic>four-valued<\/jats:italic>\n            predicate that maps access requests to either\n            <jats:italic>grant<\/jats:italic>\n            ,\n            <jats:italic>deny<\/jats:italic>\n            ,\n            <jats:italic>conflict<\/jats:italic>\n            , or\n            <jats:italic>unspecified<\/jats:italic>\n            -- the four values of the Belnap bilattice. We define an expressive access-control policy language PBel, having composition operators based on the operators of Belnap logic. Natural orderings on policies are obtained by lifting the truth and information orderings of the Belnap bilattice. These orderings lead to a query language in which policy analyses, for example, conflict freedom, can be specified. Policy analysis is supported through a reduction of the validity of policy queries to the validity of propositional formulas on predicates over access requests. We evaluate our approach through firewall policy and RBAC policy examples, and discuss domain-specific and generic extensions of our policy language.\n          <\/jats:p>","DOI":"10.1145\/1952982.1952991","type":"journal-article","created":{"date-parts":[[2011,6,6]],"date-time":"2011-06-06T11:51:38Z","timestamp":1307361098000},"page":"1-27","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":31,"title":["Access control via belnap logic"],"prefix":"10.1145","volume":"14","author":[{"given":"Glenn","family":"Bruns","sequence":"first","affiliation":[{"name":"Bell Laboratories, Alcatel-Lucent, Naperville, IL"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Huth","sequence":"additional","affiliation":[{"name":"Imperial College London, London, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2011,6,6]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/155183.155225"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0004-3702(98)00032-0"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065047"},{"volume-title":"Modern Uses of Multiple-Valued Logic","author":"Belnap N. D.","key":"e_1_2_1_4_1","unstructured":"Belnap , N. D. 1977. A useful four-valued logic . In Modern Uses of Multiple-Valued Logic , J. M. Dunn and G. Epstein Eds., D. Reidel , Dordrecht , 8--37. Belnap, N. D. 1977. A useful four-valued logic. In Modern Uses of Multiple-Valued Logic, J. M. Dunn and G. Epstein Eds., D. Reidel, Dordrecht, 8--37."},{"key":"e_1_2_1_5_1","doi-asserted-by":"crossref","unstructured":"Blaze M. Feigenbaum J. Ioannidis J. and \n      Keromytis A. D\n  . \n  1999\n  . The role of trust management in distributed systems security. In Secure Internet Programming Lecture Notes in Computer Science vol. \n  1603 Springer Berlin 185--210.   Blaze M. Feigenbaum J. Ioannidis J. and Keromytis A. D. 1999. The role of trust management in distributed systems security. In Secure Internet Programming Lecture Notes in Computer Science vol. 1603 Springer Berlin 185--210.","DOI":"10.1007\/3-540-48749-2_8"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/504909.504910"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314436.1314439"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2008.10"},{"key":"e_1_2_1_9_1","unstructured":"Bruns G. and Huth M. 2011. Access control via Belnap logic: Intuitive expressive and analyzable policy composition. Tech. rep. 2011\/6 Department of Computing Imperial College London.  Bruns G. and Huth M. 2011. Access control via Belnap logic: Intuitive expressive and analyzable policy composition. Tech. rep. 2011\/6 Department of Computing Imperial College London."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314436.1314440"},{"volume-title":"Using management center for firewalls 1.3.2. Cisco Systems","author":"CiscoWorks","key":"e_1_2_1_11_1","unstructured":"CiscoWorks . 2004. Using management center for firewalls 1.3.2. Cisco Systems , Inc . CiscoWorks. 2004. Using management center for firewalls 1.3.2. Cisco Systems, Inc."},{"volume-title":"A Discipline of Programming","author":"Dijkstra E. W.","key":"e_1_2_1_12_1","unstructured":"Dijkstra , E. W. 1976. A Discipline of Programming . Prentice Hall , Englewood Cliffs, NJ . Dijkstra, E. W. 1976. A Discipline of Programming. Prentice Hall, Englewood Cliffs, NJ."},{"volume-title":"Proceedings of the NIST-NSA National Computer Security Conference. 554--563","author":"Ferraiolo D.","key":"e_1_2_1_13_1","unstructured":"Ferraiolo , D. and Kuhn , D. R . 1992. Role-based access control . In Proceedings of the NIST-NSA National Computer Security Conference. 554--563 . Ferraiolo, D. and Kuhn, D. R. 1992. Role-based access control. In Proceedings of the NIST-NSA National Computer Security Conference. 554--563."},{"key":"e_1_2_1_14_1","unstructured":"Ferraiolo D. F. Kuhn D. R. and Chandramouli R. 2003. Role-Based Access Control 2nd Ed. Artech House Norwood MA.   Ferraiolo D. F. Kuhn D. R. and Chandramouli R. 2003. Role-Based Access Control 2nd Ed. Artech House Norwood MA."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1016\/0743-1066(91)90014-G"},{"volume-title":"Self-Reference","author":"Fitting M.","key":"e_1_2_1_16_1","unstructured":"Fitting , M. 2006. Bilattices are nice things . In Self-Reference , Center for the Study of Language and Information. Fitting, M. 2006. Bilattices are nice things. In Self-Reference, Center for the Study of Language and Information."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1111\/j.1467-8640.1988.tb00280.x"},{"volume-title":"Proceedings of the Computer Security Foundations Workshop (CSFW'03)","author":"Halpern J.","key":"e_1_2_1_18_1","unstructured":"Halpern , J. and Weissman , V . 2003. Using first-order logic to reason about policies . In Proceedings of the Computer Security Foundations Workshop (CSFW'03) . Halpern, J. and Weissman, V. 2003. Using first-order logic to reason about policies. In Proceedings of the Computer Security Foundations Workshop (CSFW'03)."},{"volume-title":"Proceedings of the 14th IEEE Workshop on Computer Security Foundations (CSFW'01)","author":"Halpern J. Y.","key":"e_1_2_1_19_1","unstructured":"Halpern , J. Y. and Meyden , R. V. D. 2001. A logical reconstruction of SPKI . In Proceedings of the 14th IEEE Workshop on Computer Security Foundations (CSFW'01) . IEEE Computer Society, Los Alamitos, CA, 59. Halpern, J. Y. and Meyden, R. V. D. 2001. A logical reconstruction of SPKI. In Proceedings of the 14th IEEE Workshop on Computer Security Foundations (CSFW'01). IEEE Computer Society, Los Alamitos, CA, 59."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/383891.383894"},{"volume-title":"Introduction to Metamathematics","author":"Kleene S. C.","key":"e_1_2_1_21_1","unstructured":"Kleene , S. C. 1952. Introduction to Metamathematics . D. Van Nostrand . Kleene, S. C. 1952. Introduction to Metamathematics. D. Van Nostrand."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1180337.1180342"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/605434.605438"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1229285.1229305"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542207.1542229"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1017753.1017789"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.161279"},{"volume-title":"Foundations for Programming Languages","author":"Mitchell J. C.","key":"e_1_2_1_28_1","unstructured":"Mitchell , J. C. 1996. Foundations for Programming Languages . MIT Press , Cambridge, MA . Mitchell, J. C. 1996. Foundations for Programming Languages. MIT Press, Cambridge, MA."},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1080\/10919399409540214"},{"key":"e_1_2_1_30_1","unstructured":"Moses T. 2005. eXtensible access control markup language (XACML). Version 2.0 Committee specification OASIS.  Moses T. 2005. eXtensible access control markup language (XACML). Version 2.0 Committee specification OASIS."},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1533057.1533097"},{"volume-title":"Proceedings of the Workshop on Database and Expert Systems Applications. IEEE","author":"Nuseibeh B.","key":"e_1_2_1_32_1","unstructured":"Nuseibeh , B. and Easterbrook , S . 1999. The process of inconsistency management: A framework for understanding . In Proceedings of the Workshop on Database and Expert Systems Applications. IEEE , Los Alamitos, CA, 364--368. Nuseibeh, B. and Easterbrook, S. 1999. The process of inconsistency management: A framework for understanding. In Proceedings of the Workshop on Database and Expert Systems Applications. IEEE, Los Alamitos, CA, 364--368."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542207.1542218"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/0004-3702(80)90014-4"},{"volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS'01)","author":"Ribeiro C.","key":"e_1_2_1_35_1","unstructured":"Ribeiro , C. , Zuquete , A. , Ferreira , P. , and Guedes , P . 2001. SPL: An access control language for security policies and complex constraints . In Proceedings of the Network and Distributed System Security Symposium (NDSS'01) . Ribeiro, C., Zuquete, A., Ferreira, P., and Guedes, P. 2001. SPL: An access control language for security policies and complex constraints. In Proceedings of the Network and Distributed System Security Symposium (NDSS'01)."},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/300830.300839"},{"volume-title":"The Structure of Typed Programming Languages","author":"Schmidt D.","key":"e_1_2_1_37_1","unstructured":"Schmidt , D. 1995. The Structure of Typed Programming Languages . The MIT Press , Cambridge, MA . Schmidt, D. 1995. The Structure of Typed Programming Languages. The MIT Press, Cambridge, MA."},{"key":"e_1_2_1_38_1","unstructured":"Sedayao J. 2001. Cisco IOS Access Lists. O'Reilly.   Sedayao J. 2001. Cisco IOS Access Lists. O'Reilly."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-1993-22-304"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1952982.1952991","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1952982.1952991","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:59:41Z","timestamp":1750244381000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1952982.1952991"}},"subtitle":["Intuitive, expressive, and analyzable policy composition"],"short-title":[],"issued":{"date-parts":[[2011,5]]},"references-count":39,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2011,5]]}},"alternative-id":["10.1145\/1952982.1952991"],"URL":"https:\/\/doi.org\/10.1145\/1952982.1952991","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"type":"print","value":"1094-9224"},{"type":"electronic","value":"1557-7406"}],"subject":[],"published":{"date-parts":[[2011,5]]},"assertion":[{"value":"2009-09-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2010-08-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-06-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}