Designing Fast and Scalable XACML Policy Evaluation Engines

Designing Fast and Scalable XACML Policy Evaluation Engines
复制标题

DOI:
10.1109/tc.2010.274
复制
发表时间:
2011-12-01
影响因子:
3.7
通讯作者:
Xie, Tao
Xie, Tao
中科院分区:
计算机科学2区
文献类型:
--
作者:
Liu, Alex X.;Chen, Fei;Xie, Tao

文献摘要

被引文献

相似文献

大多数关于策略的先前研究都集中在正确性上。虽然正确性是一个重要的问题,但如果最终的系统没有有效地实现,从而表现不佳,则基于策略的计算的采用可能会受到限制。为了提高基于策略的计算的有效性和采用,在本文中,我们提出了快速的政策评估算法,可以适应支持各种政策语言。本文重点关注XACML策略评估,因为XACML已成为指定访问控制策略的事实上的标准,已广泛用于Web服务器,并且是现有策略语言中最复杂的。我们实现了我们的算法在一个策略评估系统称为XEngine和进行并排比较与Sun的政策决策点(PDP),XACML策略评估的工业标准。结果表明,XEngine比Sun PDP快几个数量级。性能差异几乎随XACML策略中规则的数量线性增长。据我们所知,目前还没有关于改进XACML策略评估性能的工作。本文是探索这一未知空间的第一步。
Most prior research on policies has focused on correctness. While correctness is an important issue, the adoption of policy-based computing may be limited if the resulting systems are not implemented efficiently and thus perform poorly. To increase the effectiveness and adoption of policy-based computing, in this paper, we propose fast policy evaluation algorithms that can be adapted to support various policy languages. In this paper, we focus on XACML policy evaluation because XACML has become the de facto standard for specifying access control policies, has been widely used on web servers, and is most complex among existing policy languages. We implemented our algorithms in a policy evaluation system called XEngine and conducted side-by-side comparison with Sun Policy Decision Point (PDP), the industrial standard for XACML policy evaluation. The results show that XEngine is orders of magnitude faster than Sun PDP. The performance difference grows almost linearly with the number of rules in an XACML policy. To our best knowledge, there is no prior work on improving XACML policy evaluation performance. This paper represents the first step in exploring this unknown space.