{"id":{"repo_id":"calgary","oai_identifier":"oai:ucalgary.scholaris.ca:11023/468"},"canonical_url":"https://search.dev.ndltd.org/etd/calgary/oai:ucalgary.scholaris.ca:11023/468","repository":{"repo_id":"calgary","name":"University of Calgary","base_url":"https://ucalgary.scholaris.ca/server/oai/request"},"display":{"title":"A Novel Approach to White-Box Policy Analysis","abstract":"The access control systems in dynamic environments contain composite access control policies, that combine decisions from multiple component policies using policy combining algorithms. In such dynamic environments, analysis of policies is a challenge. In this thesis, I propose a white-box policy analysis Decision in Context (DIC), that would analyse component policies situated inside a composite policy. For generality, the DIC query is defined in an XACML-style policy composition framework. The DIC query is implemented via a reduction to either propositional satisfiability or pseudo boolean satisfiability instances, after which standard solvers can be invoked to complete the evaluation. Empirical analyses have been conducted to compare the relative efficiency of the SAT and PBS encodings. The latter is found to be the more effective encoding, in reducing DIC queries containing majority voting policy combining algorithms.","abstract_html":"The access control systems in dynamic environments contain composite access control policies, that combine decisions from multiple component policies using policy combining algorithms. In such dynamic environments, analysis of policies is a challenge. In this thesis, I propose a white-box policy analysis Decision in Context (DIC), that would analyse component policies situated inside a composite policy. For generality, the DIC query is defined in an XACML-style policy composition framework. The DIC query is implemented via a reduction to either propositional satisfiability or pseudo boolean satisfiability instances, after which standard solvers can be invoked to complete the evaluation. Empirical analyses have been conducted to compare the relative efficiency of the SAT and PBS encodings. The latter is found to be the more effective encoding, in reducing DIC queries containing majority voting policy combining algorithms.","abstract_has_math":false,"creators":["Balasubramaniam, Jayalakshmi"],"institution":"Graduate Studies","degree_name":"Master of Science (MSc)","degree_level":null,"degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":["Fong, Philip Wai Leung"],"committee_chairs":[],"committee_members":[],"year":2013,"date_issued":"2013-01-25","date_published":"2013-01-25","updated_at":"2026-07-24T01:30:22Z","subjects":["Computer Science"],"languages":["eng"],"rights":["University of Calgary graduate students retain copyright ownership and moral rights for their thesis. You may use this material in any way that is permitted by the Copyright Act or through licensing that has been assigned to the document. For uses that are not allowable under copyright legislation or licensing, you are required to seek permission."],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier.doi","label":"DOI","values":["http://dx.doi.org/10.11575/PRISM/24928"],"render_values":[{"text":"http://dx.doi.org/10.11575/PRISM/24928","href":"http://dx.doi.org/10.11575/PRISM/24928","code":true}]}]},"links":{"outbound_url":"http://hdl.handle.net/11023/468","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Fong, Philip Wai Leung"]},{"key":"dc:creator","label":"Author","values":["Balasubramaniam, Jayalakshmi"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2013-01-25T17:04:39Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2013-06-15T07:01:37Z"]},{"key":"dc:date.issued","label":"Date","values":["2013-01-25"]},{"key":"dc:publisher.institution","label":"Dc Publisher Institution","values":["University of Calgary"]},{"key":"dc:type","label":"Dc Type","values":["master thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science (MSc)"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Calgary"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Computer Science"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["University of Calgary graduate students retain copyright ownership and moral rights for their thesis. You may use this material in any way that is permitted by the Copyright Act or through licensing that has been assigned to the document. For uses that are not allowable under copyright legislation or licensing, you are required to seek permission."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.doi","label":"DOI","values":["http://dx.doi.org/10.11575/PRISM/24928"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["http://hdl.handle.net/11023/468"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["The access control systems in dynamic environments contain composite access control policies, that combine decisions from multiple component policies using policy combining algorithms. In such dynamic environments, analysis of policies is a challenge. In this thesis, I propose a white-box policy analysis Decision in Context (DIC), that would analyse component policies situated inside a composite policy. For generality, the DIC query is defined in an XACML-style policy composition framework. The DIC query is implemented via a reduction to either propositional satisfiability or pseudo boolean satisfiability instances, after which standard solvers can be invoked to complete the evaluation. Empirical analyses have been conducted to compare the relative efficiency of the SAT and PBS encodings. The latter is found to be the more effective encoding, in reducing DIC queries containing majority voting policy combining algorithms."]},{"key":"dc:title","label":"Title","values":["A Novel Approach to White-Box Policy Analysis"]}]}],"canonical_facts":{"dc:contributor.advisor":["Fong, Philip Wai Leung"],"dc:creator":["Balasubramaniam, Jayalakshmi"],"dc:date.accessioned":["2013-01-25T17:04:39Z"],"dc:date.available":["2013-06-15T07:01:37Z"],"dc:date.issued":["2013-01-25"],"dc:description.abstract":["The access control systems in dynamic environments contain composite access control policies, that combine decisions from multiple component policies using policy combining algorithms. In such dynamic environments, analysis of policies is a challenge. In this thesis, I propose a white-box policy analysis Decision in Context (DIC), that would analyse component policies situated inside a composite policy. For generality, the DIC query is defined in an XACML-style policy composition framework. The DIC query is implemented via a reduction to either propositional satisfiability or pseudo boolean satisfiability instances, after which standard solvers can be invoked to complete the evaluation. Empirical analyses have been conducted to compare the relative efficiency of the SAT and PBS encodings. The latter is found to be the more effective encoding, in reducing DIC queries containing majority voting policy combining algorithms."],"dc:identifier.doi":["http://dx.doi.org/10.11575/PRISM/24928"],"dc:identifier.uri":["http://hdl.handle.net/11023/468"],"dc:language.iso":["eng"],"dc:publisher.institution":["University of Calgary"],"dc:rights":["University of Calgary graduate students retain copyright ownership and moral rights for their thesis. You may use this material in any way that is permitted by the Copyright Act or through licensing that has been assigned to the document. For uses that are not allowable under copyright legislation or licensing, you are required to seek permission."],"dc:subject":["Computer Science"],"dc:title":["A Novel Approach to White-Box Policy Analysis"],"dc:type":["master thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_name":["Master of Science (MSc)"],"thesis:institution_name":["University of Calgary"]},"updated_at":"2026-07-24T01:30:22Z"}