resource bound access control proposal - #108
Open
Martin187187 wants to merge 1 commit into
Open
Martin187187 wants to merge 1 commit into
Martin187187 wants to merge 1 commit into
Conversation
| @@ -0,0 +1,82 @@ | |||
| <?xml version='1.0' encoding='utf-8'?> | |||
| <svg | |||
| xmlns='http://www.w3.org/2000/svg' | |||
| <?xml version='1.0' encoding='utf-8'?> | ||
| <svg | ||
| xmlns='http://www.w3.org/2000/svg' | ||
| xmlns:xlink='http://www.w3.org/1999/xlink' |
|
|
||
| <style> | ||
| rect, line, path { stroke-width: 1.5px; stroke: black; fill: transparent; } | ||
| rect, line, path { stroke-linecap: square; stroke-linejoin: rounded; } |
|
|
||
| <style> | ||
| rect, line, path { stroke-width: 1.5px; stroke: black; fill: transparent; } | ||
| rect, line, path { stroke-linecap: square; stroke-linejoin: rounded; } |
| <rect x='350' y='10' height='20' width='50' rx='0' ry='0' class='rule'/> | ||
| <text x='375' y='25' text-anchor='middle' class='rule'>Ws</text> | ||
| <rect x='420' y='10' height='20' width='260' rx='0' ry='0' class='rule'/> | ||
| <text x='550' y='25' text-anchor='middle' class='rule'>ResourceBoundAccessPermissionDefs</text> |
| "attributes": [{"CLAIM": "role"}], | ||
| } | ||
| ], | ||
| "DEFACLS": [ |
| { | ||
| "name": "readers-can-read", | ||
| "acl": { | ||
| "USEATTRIBUTES": "readers", |
| }, | ||
| } | ||
| ], | ||
| "DEFFORMULAS": [ |
| ], | ||
| "rules": [ | ||
| { | ||
| "USEACL": "readers-can-read", |
| "rules": [ | ||
| { | ||
| "USEACL": "readers-can-read", | ||
| "USEFORMULA": "is-reader", |
Martin187187
marked this pull request as ready for review
September 4, 2026 15:29
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
The existing object-based Access Rule Model is very flexible, but for hierarchical AAS data it can become difficult to model and understand larger access-control configurations.
Today, access rules are defined first and their target resources are selected through
OBJECTS:To determine the policy of
Submodel A, all Access Rules need to be considered to find the rules that reference this resource.The resource-bound view turns this around:
This makes access rules easier to model, understand and maintain, because all rules governing one resource are grouped together and the resource does not need to be repeated in every rule.
Natural fit for hierarchical AAS data
The AAS information model is inherently hierarchical:
Resource-bound policies can follow exactly the same structure.
For example, consider a
TechnicalDataSubmodel that is generally readable by customers, except for one internal property:Instead of explicitly assigning the customer rules to every individual SubmodelElement, the common policy can be defined once at the Submodel level. Only resources requiring different access rules need their own Resource-Bound Access Rule Model.
This keeps the security model close to the structure of the protected data and makes exceptions easy to identify.
Established access-control pattern
Scoping permissions to resources and applying permissions along a resource hierarchy is also a common pattern in existing access-control systems.
Examples include file-system ACLs, where permissions can be associated with an object and inherited by child objects, and cloud IAM systems, where permissions are assigned at a particular resource scope and can apply to resources below that scope.
The proposed resource-bound view applies the same general principle to the AAS hierarchy while keeping the existing ABAC concepts of Part 4.
Small Extension of the Existing Model
This does not require a new authorization mechanism.
The existing:
RIGHTSremain unchanged.
The main structural difference is simply:
versus:
The existing object-based representation remains available for use cases where a global rule-oriented view is more suitable.
The resource-bound representation therefore provides an additional, more natural way to model policies for hierarchical AAS data without replacing the existing model.