Extending XACML to support Credential Based Hybrid Access Control
نویسندگان
چکیده
Various research efforts are in progress to enforce credential based access control using XACML standard. The current standard of XACML supports attribute based access control [4,5,9,19]. While XACML accepts certified attributes through digital certificates, it does not support credential based access control in which the access conditions are defined not only in terms of credential attributes but also in terms of types of credentials. Credential based hybrid access control[7,11,14,20,21] has been proposed for systems having diversified access control requirements. The use of various types of credentials in access control policy specification provides easy and immediate access to unknown user in open access environment. Fine grained access control in closed administrative domain is achieved using Identity Credential and the attributes associated with the credentials. In this paper, we propose extensions to the XACML standard that support credential-based hybrid access control. The XACML access policy language has been extended to define access policy in terms of heterogeneous credentials. Each credential is uniquely identified by associating a category and type with it. The access policy contains various conditions over credentials and the attributes associated with the credentials. Enhancement to XACML framework has also been proposed so that credential based hybrid access policies can be evaluated and enforced. .
منابع مشابه
Offline Expansion of XACML Policies
In the last few years XML-based access control languages like XACML have been increasingly used for specifying complex policies regulating access to network resources. Today, growing interest in Semantic-Web style metadata for describing resources and users is stimulating research on how to express access control policies based on advanced descriptions rather than on single attributes. In this ...
متن کاملCredential-Based Access Control Extensions to XACML
Access control and authentication systems are currently undergoing a paradigm shift towards openness and user-centricity where service providers communicate to the users what information they need to provide to gain access to a given resource. This paradigm shift is a crucial step towards allowing users to manage their identities and privacy. To ensure the service provider of the validity of th...
متن کاملAccess Management in Federated Digital Libraries
With the growth in digital libraries and standardization of protocols for metadata sharing, it is becoming feasible to build federated discovery services which aggregate metadata from different digital libraries (data providers) and provide a unified search interface to users. One of the obstacles that keep data providers, especially the commercial ones, from joining the federation is the lack ...
متن کاملA XML Policy-Based Approach for RSVP
This work proposes a XML-based framework for distributing and enforcing RSVP access control policies, for RSVP-aware application servers. Policies are represented by extending XACML, the general purpose access control language proposed by OASIS. Because RSVP is a specific application domain, it is not directly supported by the XACML standard. Hence, this work defines the XACML extensions requir...
متن کاملOffline Expansion of XACML Policies Based on P3P Metadata
In the last few years XML-based access control languages like XACML have been increasingly used for specifying complex policies regulating access to network resources. Today, growing interest in semanticWeb style metadata for describing resources and users is stimulating research on how to express access control policies based on advanced descriptions rather than on single attributes. In this p...
متن کامل