Resolving Policy Conflicts - Integrating Policies from Multiple Authors
نویسندگان
چکیده
In this paper we show that the static conflict resolution strategy of XACML is not always sufficient to satisfy the policy needs of an organisation where multiple parties provide their own individual policies. Different conflict resolution strategies are often required for different situations. Thus combining one or more sets of policies into a single XACML ‘super policy’ that is evaluated by a single policy decision point (PDP), cannot always provide the correct authorisation decision, due to the static conflict resolution algorithms that have to be built in. We therefore propose a dynamic conflict resolution strategy that chooses different conflict resolution algorithms based on the authorisation request context. The proposed system receives individual and independent policies, as well as conflict resolution rules, from different policy authors, but instead of combining these into one super policy with static conflict resolution rules, each policy is evaluated separately and the conflicts among their authorisation decisions is dynamically resolved using the conflict resolution algorithm that best matches the authorisation decision request. It further combines the obligations of independent policies returning similar decisions which XACML can’t do while keeping each author’s policy intact.
منابع مشابه
Policy Conflicts in Home Care Systems
Technology to support care at home is a promising alternative to traditional approaches. However, home care systems present significant technical challenges. For example, it is difficult to make such systems flexible, adaptable, and controllable by users. The authors have created a prototype system that uses policy-based management of home care services. Conflict detection and resolution for ho...
متن کاملSensor Network Policy Conflicts
Policy conflict is the equivalent of feature interaction in traditional services. Conflicts between the actions of policies occur at execution time. Potential conflicts must be detected and resolved. Using an established policy system and core language, a specialised policy language for wireless sensor network management has been defined. This short paper describes the policy language and discu...
متن کاملStatic Analysis to Avoid Overlap of Policies in Policy-based Management Systems
A management policy evolves over time by addition, deletion and modifications of rules. Policies authored by different administrators may be merged to form the final system management policy. Since policies are used to govern the system behavior, conflicts may arise in the set of policies and also may arise during the refinement process, between the high-level goals and the implementable polici...
متن کاملParticipating Policy Usage Evidence from Stock Life Insurers
Extant literature demonstrates that participating policies mitigate shareholder-policyholder incentive conflicts in stock insurance firms. However, extending the argument in Mayers and Smith (1994), the authors formally show that participating policies also exacerbate the shareholder-manager incentive conflicts in stock insurance firms. In this article, the authors test whether hypotheses deriv...
متن کاملMetacognition for Detecting and Resolving Conflicts in Operational Policies
Informational conflicts in operational policies cause agents to run into situations where responding based on the rules in one policy violates the same or another policy. Static checking of these conflicts is infeasible and impractical in a dynamic environment. This paper discusses a practical approach to handling policy conflicts in real-time domains within the context of a hierarchical milita...
متن کامل