发表机构
Apple Inc.(苹果公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出一个基于LLM的系统,通过结构化分解和模式验证将自然语言访问控制策略转换为Rego代码,在372条ACRE语句上实现50.3%的端到端正确率,较基线提升3.3倍,显著增强了策略生成的可靠性。
AI 中文摘要
本文提出一个基于大语言模型(LLM)的系统,将自然语言访问控制策略(NLACPs)转换为可执行的 Rego 代码,用于 Open Policy Agent(OPA)。该系统提供了一个模块化的端到端流水线,涵盖策略检测、组件提取、模式验证、代码检查(linting)、编译以及自动化测试生成与执行。该系统旨在弥合人类可读的访问需求与机器可执行的策略即代码(PaC)之间的差距,重点关注部署可靠性和安全正确性。我们在 372 条具有非空主体、动作和资源注释的 ACRE 完整访问控制语句上,以直接单提示 LLM 基线为对照,评估了该系统,以隔离结构化分解和模式感知验证的贡献。该系统实现了 50.3% 的端到端策略正确率,而基线为 15.3%,提升了 3.3 倍。一条策略只有在满足编译、代码检查以及正面和负面测试时才算正确,这是对可部署正确性的严格度量。在安全关键模式上,该系统为 87.5% 的拒绝策略生成了正确的拒绝语义(基线:37.5%),为 100% 的所有权限定策略生成了所有权条件(基线:40%),并为 100% 的状态限定策略生成了状态限定条件(基线:55.6%)。这些结果表明,结构化分解和模式感知验证在提高 LLM 生成的授权策略的可靠性方面发挥着关键作用。
英文摘要
This paper presents an LLM-based system that translates natural-language access control policies (NLACPs) into executable Rego code for Open Policy Agent (OPA). It provides a modular, end-to-end pipeline for policy detection, component extraction, schema validation, linting, compilation, and automated test generation and execution. The system is designed to bridge the gap between human-readable access requirements and machine-enforceable policy-as-code (PaC), with a focus on deployment reliability and security correctness. We evaluate the system on 372 ACRE-complete access control statements with non-null subject, action, and resource annotations against a direct single-prompt LLM baseline to isolate the contribution of structured decomposition and schema-aware validation. The system achieves a 50.3% end-to-end policy correctness rate, compared with 15.3% for the baseline, representing a 3.3x improvement. A policy is counted as correct only if it satisfies compilation, linting, and both positive and negative tests, making this a strict measure of deployable correctness. On security-critical patterns, the system generates correct deny semantics for 87.5% of deny policies (baseline: 37.5%), ownership conditions for 100% of ownership-qualified policies (baseline: 40%), and status-qualified conditions for 100% of status-qualified policies (baseline: 55.6%). These results indicate that structured decomposition and schema-aware validation play a critical role in improving the reliability of LLM-generated authorization policies.