Arid
A Non-Technical XACML Target Editor for Dynamic Access Control Systems
Stepien, Bernard1; Felty, Amy1; Matwin, Stan2
通讯作者Stepien, Bernard
会议名称International Conference on Collaboration Technologies and Systems (CTS)
会议日期MAY 19-23, 2014
会议地点Minneapolis, MN
英文摘要

XACML is a powerful and flexible access control (AC) policy language. It is an OASIS standard that is now widely used in a variety of applications, particularly those that require interoperability between AC systems. The language definition includes a precise grammar, syntax, and semantics, and it is both expressive and verbose. This combination of expressive power and verbosity can lead to difficulty in understanding the language's syntax and semantics for both technical and nontechnical users alike. As a result, reducing the difficulty of editing XACML policies has become an intense area of research. In our own work in this area, we previously showed how to render complex XACML conditions using a non-technical display notation and showed that it is easy to use this notation with interactive plain text editors that do not require any technical coding. Although XACML conditions are expressive and flexible, XACML targets are actually the most commonly used XACML language construct. They have an additional level of complexity, especially in version 3.0, due to the fact that the form and kinds of XACML constructs allowed in targets is much more limited. This paper extends our previous work, showing how the same powerful and flexible interactive editing principles can be applied to targets in order to allow users to use natural logic rather than implementation logic. We extend these principles and fully integrate them into our editing tool, easyXACML. This tool is usable by users with no technical knowledge of XACML, thus making XACML totally transparent to the user, while still retaining all of its functionalities and semantics. Our tool thus allows users to focus on policy logic rather than on details of syntax. As a result, the risk of errors in policies is greatly reduced.


英文关键词component Access control XACML policy administration point ABAC RBAC
来源出版物PROCEEDINGS OF THE 2014 INTERNATIONAL CONFERENCE ON COLLABORATION TECHNOLOGIES AND SYSTEMS (CTS)
出版年2014
页码150-157
EISBN978-1-4799-5158-1
出版者IEEE
类型Proceedings Paper
语种英语
国家Canada
收录类别CPCI-S
WOS记录号WOS:000345833000024
WOS类目Computer Science, Hardware & Architecture ; Computer Science, Information Systems
WOS研究方向Computer Science
资源类型会议论文
条目标识符http://119.78.100.177/qdio/handle/2XILL650/303436
作者单位1.Univ Ottawa, Sch Elect Engn & Comp Sci, Ottawa, ON, Canada;
2.Dalhousie Univ, Polish Acad Sci, Fac Comp Sci, Canada Inst Comp Sci, Halifax, NS, Canada
推荐引用方式
GB/T 7714
Stepien, Bernard,Felty, Amy,Matwin, Stan. A Non-Technical XACML Target Editor for Dynamic Access Control Systems[C]:IEEE,2014:150-157.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Stepien, Bernard]的文章
[Felty, Amy]的文章
[Matwin, Stan]的文章
百度学术
百度学术中相似的文章
[Stepien, Bernard]的文章
[Felty, Amy]的文章
[Matwin, Stan]的文章
必应学术
必应学术中相似的文章
[Stepien, Bernard]的文章
[Felty, Amy]的文章
[Matwin, Stan]的文章
相关权益政策
暂无数据
收藏/分享

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。