AcVerifier: Cross-Domain Access Control Verification via Hybrid Static and Dynamic Analysis

Jie Zhang, Yuanyuan He, Miao Hu, Xinwei Yu, Tingting Guo, Xiangyu Gao, Jiaqi Ma · 2024

In today’s interconnected world, as the scale of data sharing across diverse systems and organizations continues to grow, the secure and verifiable access to these data is of escalating importance. Nonetheless, existing verification methods for prevalent access control models, such as Role-Based Access Control (RBAC), usually face several prevalent challenges, including inadequate support for cross-domain operations, potential systemic risks stemming from potential flaws in policy design and improper implementation in large-scale complex systems, and concerns about modeling credibility. To address the issues, we propose AcVerifier, a novel solution that employs blockchain technology coupled with deterministic finite automaton (DFA) to enable verifiable enforcement of access control policies across disparate domains. AcVerifier uploads data indices and policies to a secure authorization server, which records operation logs in blockchain-connected data containers, thereby ensuring data credibility. AcVerifier employs a hybrid verification method combining static and dynamic analysis techniques, leveraging their respective strengths for preemptive auditing and real-time monitoring. Thus, AcVerifier can verify the correctness and consistency between the permissions granted by the extended access control policies and their actual execution in cross-domain data sharing and ubiquitous circulation scenarios. Here, the permissions encompass desensitization, access, modification and forwarding of personal information. Comprehensive evaluation demonstrates the correctness and efficiency of AcVerifier in addressing the challenges of cross-domain access control verification.

Read the paper · More papers on PaperTik