paper

Safety Analysis in the NGAC Model

arXiv:2505.06406 · doi:10.1145/3734436.3734444

Abstract

We study the safety problem for the next-generation access control (NGAC) model. We show that under mild assumptions it is coNP-complete, and under further realistic assumptions we give an algorithm for the safety problem that significantly outperforms naive brute force search. We also show that real-world examples of mutually exclusive attributes lead to nearly worst-case behavior of our algorithm.

8 pages, to appear in SACMAT 2025