XACML and Risk-Aware Access Control

نویسنده

  • Luca Gasparini
چکیده

Over the last few years there has been a rapid development of technologies such as ubiquitous computing and distributed multi-agent systems. As a consequence an increasing need to share information securely in a distributed dynamic environment has arisen. Risk-aware access control (RAAC) has recently shown promise as an approach to addressing this need of flexible and dynamical access control requirements. Additionally, OASIS proposed XACML as a new standard XML-based language for writing access control policies, requests and responses. The standard specification also defines reference architecture for implementing an XACML based system. Despite the fact that XACML is designed to support various access control models, we believe it doesn’t provide a natural way for defining RAAC policies. In this paper we propose an approach that uses standard XACML features to implement RAAC. In particular, we abstract core components of RAAC relevant to risk assessment and risk mitigation, and illustrate how to define XACML policies to implement these components. We also propose a modular architecture for the XACML obligations service to handle both system and user obligations, which are typically used as risk mitigation methods in RAAC.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A XML Policy-Based Approach for RSVP

This work proposes a XML-based framework for distributing and enforcing RSVP access control policies, for RSVP-aware application servers. Policies are represented by extending XACML, the general purpose access control language proposed by OASIS. Because RSVP is a specific application domain, it is not directly supported by the XACML standard. Hence, this work defines the XACML extensions requir...

متن کامل

Mobile Security with Location-Aware Role-Based Access Control

This paper describes how location-aware Role-Based Access Control (RBAC) can be implemented on top of the Geographically eXtensible Access Control Markup Language (GeoXACML). It furthermore sketches how spatial separation of duty constraints (both static and dynamic) can be implemented using GeoXACML on top of the XACML RBAC profile. The solution uses physical addressing of geographical locatio...

متن کامل

Extending Policy Languages to the Semantic Web

In the semantic web environment it is important to be able to specify access control requirements about subjects accessing the information and about resources to be accessed in terms of the rich ontologybased metadata describing them. In this paper, we outline how current standard policy languages such as XACML can be extended to address this issue. Then, we describe a reference architecture fo...

متن کامل

A Semantic-Aware Attribute-Based Access Control Model for Web Services

Web service is a new service-oriented computing paradigm which poses the unique security challenges due to its inherent heterogeneity, multidomain characteristic and highly dynamic nature. A key challenge in Web services security is the design of effective access control schemes. Attribute-based access control (ABAC) is more appropriate than some other access control mechanisms, but it do not f...

متن کامل

Access Negotiation within XACML Architecture

Web services offer a possibility of exchanging data between entities from different organizational bounderies. Keeping sensitive resources private in a public world is a common concern of service providers. Thus, there is a need for access control management at the level of the web services in addition to a prior negotiation of access. This negotiation is the first step in the access control ma...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013