XACML and Risk-Aware Access Control
نویسنده
چکیده
Over the last few years there has been a rapid development of technologies such as ubiquitous computing and distributed multi-agent systems. As a consequence an increasing need to share information securely in a distributed dynamic environment has arisen. Risk-aware access control (RAAC) has recently shown promise as an approach to addressing this need of flexible and dynamical access control requirements. Additionally, OASIS proposed XACML as a new standard XML-based language for writing access control policies, requests and responses. The standard specification also defines reference architecture for implementing an XACML based system. Despite the fact that XACML is designed to support various access control models, we believe it doesn’t provide a natural way for defining RAAC policies. In this paper we propose an approach that uses standard XACML features to implement RAAC. In particular, we abstract core components of RAAC relevant to risk assessment and risk mitigation, and illustrate how to define XACML policies to implement these components. We also propose a modular architecture for the XACML obligations service to handle both system and user obligations, which are typically used as risk mitigation methods in RAAC.
منابع مشابه
A XML Policy-Based Approach for RSVP
This work proposes a XML-based framework for distributing and enforcing RSVP access control policies, for RSVP-aware application servers. Policies are represented by extending XACML, the general purpose access control language proposed by OASIS. Because RSVP is a specific application domain, it is not directly supported by the XACML standard. Hence, this work defines the XACML extensions requir...
متن کاملMobile Security with Location-Aware Role-Based Access Control
This paper describes how location-aware Role-Based Access Control (RBAC) can be implemented on top of the Geographically eXtensible Access Control Markup Language (GeoXACML). It furthermore sketches how spatial separation of duty constraints (both static and dynamic) can be implemented using GeoXACML on top of the XACML RBAC profile. The solution uses physical addressing of geographical locatio...
متن کاملExtending Policy Languages to the Semantic Web
In the semantic web environment it is important to be able to specify access control requirements about subjects accessing the information and about resources to be accessed in terms of the rich ontologybased metadata describing them. In this paper, we outline how current standard policy languages such as XACML can be extended to address this issue. Then, we describe a reference architecture fo...
متن کاملA Semantic-Aware Attribute-Based Access Control Model for Web Services
Web service is a new service-oriented computing paradigm which poses the unique security challenges due to its inherent heterogeneity, multidomain characteristic and highly dynamic nature. A key challenge in Web services security is the design of effective access control schemes. Attribute-based access control (ABAC) is more appropriate than some other access control mechanisms, but it do not f...
متن کاملAccess Negotiation within XACML Architecture
Web services offer a possibility of exchanging data between entities from different organizational bounderies. Keeping sensitive resources private in a public world is a common concern of service providers. Thus, there is a need for access control management at the level of the web services in addition to a prior negotiation of access. This negotiation is the first step in the access control ma...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2013