Knowledge Resource Center for Ecological Environment in Arid Area
Advantages of a Non-Technical XACML Notation in Role-Based Models | |
Stepien, Bernard1,2; Matwin, Stan1,2,3; Felty, Amy1,2 | |
通讯作者 | Stepien, Bernard |
会议名称 | 9th Annual International Conference on Privacy, Security and Trust |
会议日期 | JUL 19-21, 2011 |
会议地点 | Montreal, CANADA |
英文摘要 | As applications requiring access control and the environments in which they operate in become more complex, an acute need for better ways to manage access control rules has arisen. Decentralized access control, for example, requires sophisticated techniques for conflict detection and for managing rules across multiple applications with different rule formats. XACML is an OASIS standard whose interoperability qualities help in solving the latter problem. XACML has its own limitations, however. In particular, although it has the expressive power to specify very complex conditions like those needed in the ABAC (Attribute Based Access Control) model, users tend to avoid using its full power because of its verbosity. In this paper, we show how a non-technical notation we have proposed in our earlier work resolves this difficulty and allows users to work with a very compact and readable form of XACML rules, thus allowing them to take advantage of XACML's full expressive power. This expressive power can be exploited to write policies that are better organized. It can be easier, for example, to write a single possibly complex rule to cover a particular aspect of a policy as opposed to distributing the complexity over several rules with simpler conditions. As a result, policies are smaller, more compact, and easier to understand. Policy development becomes more manageable, allowing users to concentrate on the more central issue of choosing the model (RBAC, ABAC, PBAC or other) that is best suited to a particular application and policy. We show that using the full expressive power to better organize policies has a significant positive impact on PDP performance. |
英文关键词 | XACML notation access control PDP performance |
来源出版物 | 2011 NINTH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST |
ISSN | 1712-364X |
出版年 | 2011 |
页码 | 193-200 |
EISBN | 978-1-4577-0584-7 |
出版者 | IEEE |
类型 | Proceedings Paper |
语种 | 英语 |
国家 | Canada;Poland |
收录类别 | CPCI-S |
WOS记录号 | WOS:000410274300028 |
WOS类目 | Computer Science, Information Systems ; Computer Science, Theory & Methods ; Engineering, Electrical & Electronic |
WOS研究方向 | Computer Science ; Engineering |
资源类型 | 会议论文 |
条目标识符 | http://119.78.100.177/qdio/handle/2XILL650/299877 |
作者单位 | 1.Univ Ottawa, Sch Informat Technol & Engn, Ottawa, ON, Canada; 2.Devera Log Inc, Ottawa, ON, Canada; 3.Polish Acad Sci, Inst Comp Sci, Warsaw, Poland |
推荐引用方式 GB/T 7714 | Stepien, Bernard,Matwin, Stan,Felty, Amy. Advantages of a Non-Technical XACML Notation in Role-Based Models[C]:IEEE,2011:193-200. |
条目包含的文件 | 条目无相关文件。 |
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。