Supporting RBAC with XACML+OWL

Supporting RBAC with XACML+OWL
复制标题

使用 XACML OWL 支持 RBAC

DOI:
10.1145/1542207.1542231
复制
发表时间:
2009
期刊:
Third International Symposium on Information Assurance and Security
影响因子:
--
通讯作者:
E. Bertino
E. Bertino
中科院分区:
--
文献类型:
--
作者:
R. Ferrini;E. Bertino

文献摘要

被引文献

相似文献

XACML本身并不支持RBAC,即使是专门的XACML配置文件也不能支持许多相关的约束,如静态和动态的职责分离。然而,扩展XACML以支持这样的约束是一个问题,它不仅需要扩展XACML语言,还需要扩展XACML参考体系结构和引擎。在本文中,我们介绍了XACML+OWL,一个框架,集成了OWL本体和XACML策略支持RBAC。其基本思想是通过OWL本体对角色层次结构和约束进行建模,使用XACML对授权策略进行建模,从而解耦RBAC系统的设计。在这样做,我们引入了新的功能,扩展策略的语义推理服务的基础上OWL本体。作为这样的扩展的一部分,我们扩展的参考架构的XACML和XACML数据流的访问控制决策与调用这些功能。
XACML does not natively support RBAC and even the pecialized XACML profiles are not able to support many relevant constraints such as static and dynamic separation of duty. Extending XACML to support such constraints, however, is an issue that requires extensions not only to the XACML language but also to the XACML reference architecture and engine. In this paper we introduce XACML+OWL, a framework that integrates OWL ontologies and XACML policies for supporting RBAC. The basic idea is to decouple the design of an RBAC system by modeling the role hierarchy and the constraints with an OWL ontology and the authorization policies with XACML. In doing this, we introduce new functions that extend policies with semantic reasoning services based on the OWL ontology. As part of such extension, we extend the reference architecture of XACML and the XACML data-flow for access control decisions with the invocation of such functions.