Re: TAC + roles + resource access control = UAC

On 02.09.2012 16:46, bergi wrote:
> The Skype call starts in 15 minutes. Contact me on Skype if you would
> like to join.
>
> Skype-Name: bergos123

Summary of the meeting:
1. I create class diagram of current UAC version [1]
2. We think about:
2.1. modify ontology to be more close to RBAC_1 or RBAC_2 model [2]. I 
think that it will be good to base our ontology on mathematically proven 
models. [bergi, domel]
2.2. add possible to define default policy (add DefaultPolicy class, 
Deny and Allow subclasses) - I will prepare some examples to next 
meeting [domel]
3. We agreed to change:
3.1. add temporal values (using OWL-Time [3]), i.e. to define time when 
rules are valid [domel]
3.2. add a superclass (abstract class) called operation or action to 
group (sub)class Read and Write. So that extand the ontology to other 
operations. [domel]
3.3. add some OWL vocabluary to clarify dependence i.e. class 
constructions, property constructions, constraints etc (equivalentClass 
to WAC [4] and many many more) [domel]
3.4. differentiate property names and class names. Now there are many 
properties and classes, which have the same names. I want change it by 
adding prefixes, i.e. filter -> hasFilter [bergi]
4. We're not quite agree on whether or not to add new operations. I 
propose add two Updare and Remove classes. Then it can be mapped to REST 
operations:
GET - Read,
POST - Write,
PUT - Update,
DELETE - Remove.
Bergi is able to agree to these operations. [domel]

* In square bracket there is nick who prepare that point to next teleconf.


[1] 
http://desmond.imageshack.us/Himg255/scaled.php?server=255&filename=uacu.png&res=landing
[2] http://csrc.nist.gov/rbac/sandhu96.pdf
[3] http://www.w3.org/2006/time#
[4] http://www.w3.org/ns/auth/acl

Cheers,
Dominik 'domel' Tomaszuk

Received on Sunday, 2 September 2012 18:26:31 UTC