Relating Declarative Semantics and Usability in Access Control

dc.comment.hiddenParts of this thesis were published at Proceedings of the Eighth Symposium on Usable Privacy and Security and A paper was published which is now in the ACM digital library http://dl.acm.org/citation.cfm?id=2335375en
dc.contributor.authorKrishnan, Vivek
dc.date.accessioned2012-08-29T13:43:11Z
dc.date.available2012-08-29T13:43:11Z
dc.date.issued2012-08-29T13:43:11Z
dc.date.submitted2012
dc.description.abstractThis thesis addresses the problem of usability in the context of administration of access control systems. We seek to relate the notion of declarative semantics, a recurring theme in research in access control, with usability. We adopt the concrete context of POSIX ACLs and the traditional interface for it that comprises two utilities getfacl and setfacl. POSIX ACLs are the de facto standard to which POSIX conformant systems such as Linux and OpenBSD adhere. The natural semantics of getfacl and setfacl is operational. By operational we mean that the semantics of these are speci ed procedurally. We have designed and implemented an alternate interface that we call askfacl whose natural semantics is declarative. Declarative semantics means "what you see is what it is." We also discuss our design of askfacl and articulate the following thesis that underlies our work: If the natural semantics of the interface for ACLs is declarative, then a user is able to more quickly, accurately and confidently, inspect and edit ACLs than if the semantics is operational. To validate our thesis we conducted a between participant human-subject usability study with 42 participants. The results of our study measurably demonstrate the goodness of declarative semantics in access control.en
dc.identifier.urihttp://hdl.handle.net/10012/6893
dc.language.isoenen
dc.pendingfalseen
dc.publisherUniversity of Waterlooen
dc.subjectUsabilityen
dc.subjectSecurityen
dc.subjectAccess Controlen
dc.subject.programElectrical and Computer Engineeringen
dc.titleRelating Declarative Semantics and Usability in Access Controlen
dc.typeMaster Thesisen
uws-etd.degreeMaster of Applied Scienceen
uws-etd.degree.departmentElectrical and Computer Engineeringen
uws.peerReviewStatusUnrevieweden
uws.scholarLevelGraduateen
uws.typeOfResourceTexten

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Krishnan_Vivek.pdf
Size:
1.87 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
247 B
Format:
Item-specific license agreed upon to submission
Description: