IEEE Transactions on Dependable and Secure Computing

IEEE Transactions on Dependable and Secure Computing (TDSC) is a bimonthly journal that publishes archival research results focusing on foundations, methodologies, and mechanisms that support the achievement—through design, modeling, and evaluation—of systems and networks that are dependable and secure to the desired degree without compromising performance. Read the full scope of TDSC

From the September/October 2016 issue

Safety Decidability for Pre-Authorization Usage Control with Finite Attribute Domains

By P.V. Rajkumar and Ravi Sandhu

This paper considers the safety problem for the pre-authorization sub-model of the well-known $UCON_{ABC}$ usage control model, that is, $Pre\_UCON_A$ . It is shown that $Pre\_UCON_A$ with finite attribute domains has decidable safety even if arbitrary object creation is allowed. This result eliminates the previously known restrictions for obtaining safety decidability in this context, which only allow a finite bounded number of objects to be created. Our result specifically permits unbounded object creation, so the set of objects is potentially infinite. In the proof, we show that the set of reachable protection tuples in infinite state $Pre\_UCON_A$ models is finite and computable. We also provide a construction for decision procedure which answers the safety question by examining the reachable protection tuples.

