An extended RBAC profile of XACML

An extended RBAC profile of XACML
复制标题

XACML 的扩展 RBAC 配置文件

DOI:
10.1145/1180367.1180372
复制
发表时间:
2006
期刊:
--
影响因子:
--
通讯作者:
Hervé Debar
Hervé Debar
中科院分区:
--
文献类型:
--
作者:
D. A. Haidar;N. Cuppens;F. Cuppens;Hervé Debar

文献摘要

被引文献

相似文献

如今,许多组织使用安全策略来控制对敏感资源的访问。此外,交换或共享服务和资源对于这些组织实现其业务目标至关重要。由于可扩展访问控制标记语言(XACML)是由OASIS社区标准化的,因此它已被广泛部署,使得与使用相同标准语言的其他应用程序进行互操作变得更加容易。OASIS定义了XACML的RBAC概要文件,它说明了希望使用RBAC模型的组织如何在这个标准语言中表达他们的访问控制策略。这项工作分析了XACML的RBAC配置文件,显示其局限性,以响应所有的访问控制的要求。然后,我们建议在XACML的扩展RBAC配置文件中添加一些功能。预计这一新的配置文件将满足更高级的访问控制要求,如用户-用户授权、访问要素抽象和政策的上下文适用性。
Nowadays many organizations use security policies to control access to sensitive resources. Moreover, exchanging or sharing services and resources is essential for these organizations to achieve their business objectives. Since the eXtensible Access Control Markup Language (XACML) was standardized by the OASIS community, it has been widely deployed, making it easier to interoperate with other applications using the same standard language. The OASIS has defined an RBAC profile of XACML that illustrates how organizations that would like to use the RBAC model can express their access control policy within this standard language. This work analyzes the RBAC profile of XACML, showing its limitations to respond to all the requirements for access control. We then suggest adding some functionalities within an extended RBAC profile of XACML. This new profile is expected to respond to more advanced access control requirements such as user-user delegation, access elements abstractions and contextual applicability of the policies.