Arid
Advantages of a Non-Technical XACML Notation in Role-Based Models
Stepien, Bernard1,2; Matwin, Stan1,2,3; Felty, Amy1,2
通讯作者Stepien, Bernard
会议名称9th Annual International Conference on Privacy, Security and Trust
会议日期JUL 19-21, 2011
会议地点Montreal, CANADA
英文摘要

As applications requiring access control and the environments in which they operate in become more complex, an acute need for better ways to manage access control rules has arisen. Decentralized access control, for example, requires sophisticated techniques for conflict detection and for managing rules across multiple applications with different rule formats. XACML is an OASIS standard whose interoperability qualities help in solving the latter problem. XACML has its own limitations, however. In particular, although it has the expressive power to specify very complex conditions like those needed in the ABAC (Attribute Based Access Control) model, users tend to avoid using its full power because of its verbosity. In this paper, we show how a non-technical notation we have proposed in our earlier work resolves this difficulty and allows users to work with a very compact and readable form of XACML rules, thus allowing them to take advantage of XACML's full expressive power. This expressive power can be exploited to write policies that are better organized. It can be easier, for example, to write a single possibly complex rule to cover a particular aspect of a policy as opposed to distributing the complexity over several rules with simpler conditions. As a result, policies are smaller, more compact, and easier to understand. Policy development becomes more manageable, allowing users to concentrate on the more central issue of choosing the model (RBAC, ABAC, PBAC or other) that is best suited to a particular application and policy. We show that using the full expressive power to better organize policies has a significant positive impact on PDP performance.


英文关键词XACML notation access control PDP performance
来源出版物2011 NINTH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST
ISSN1712-364X
出版年2011
页码193-200
EISBN978-1-4577-0584-7
出版者IEEE
类型Proceedings Paper
语种英语
国家Canada;Poland
收录类别CPCI-S
WOS记录号WOS:000410274300028
WOS类目Computer Science, Information Systems ; Computer Science, Theory & Methods ; Engineering, Electrical & Electronic
WOS研究方向Computer Science ; Engineering
资源类型会议论文
条目标识符http://119.78.100.177/qdio/handle/2XILL650/299643
作者单位1.Univ Ottawa, Sch Informat Technol & Engn, Ottawa, ON, Canada;
2.Devera Log Inc, Ottawa, ON, Canada;
3.Polish Acad Sci, Inst Comp Sci, Warsaw, Poland
推荐引用方式
GB/T 7714
Stepien, Bernard,Matwin, Stan,Felty, Amy. Advantages of a Non-Technical XACML Notation in Role-Based Models[C]:IEEE,2011:193-200.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Stepien, Bernard]的文章
[Matwin, Stan]的文章
[Felty, Amy]的文章
百度学术
百度学术中相似的文章
[Stepien, Bernard]的文章
[Matwin, Stan]的文章
[Felty, Amy]的文章
必应学术
必应学术中相似的文章
[Stepien, Bernard]的文章
[Matwin, Stan]的文章
[Felty, Amy]的文章
相关权益政策
暂无数据
收藏/分享

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。