Managing XACML systems in distributed environments through Meta-Policies

被引:13
|
作者
Diaz-Lopez, Daniel [1 ]
Dolera-Tormo, Gines [1 ]
Gomez-Marmol, Felix [2 ]
Martinez-Perez, Gregorio [1 ]
机构
[1] Univ Murcia, Dept Ingn Informac & Comun, E-30100 Murcia, Spain
[2] NEC Labs Europe, D-69115 Heidelberg, Germany
关键词
XACML; Access control system; Distributed environments; SAML; Access control policy; Policy management;
D O I
10.1016/j.cose.2014.10.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Policy-based authorization systems have been largely deployed nowadays to control different privileges over a big amount of resources within a security domain. With policies it is possible to reach a fine-grained level of expressiveness to state proper responses of a system against multiple access control requests. In this context, XACML has achieved a big popularity between both industry and academy as a standard for the definition of access control policies, as well as an architecture for the evaluation of authorization requests and for the issuing of authorization decisions. However, the applicability of XACML is still not clear in collaborative and distributed environments composed of several security domains sharing the access control over some specific resources. Such a circumstance manifests when many security domains can simultaneously define the behavior that a resource will have upon received authorization requests, like for instance an organization with many subsidiaries, a company with a service virtualization business model, etc. In this paper we propose a solution to reach an effective distributed policy management considering that a number of policies in one domain may be confidential. To this end, the default XACML architecture has been redefined in order to use i) Master and Slave PAPs to communicate security domains, ii) Meta-Policies, to define privileges over access control policies (the policies become the managed resources) and iii) SAML extensions to protect the policy management messages which flow between security domains. The experiments and the defined scenarios in the paper prove the validity of the proposed solution. (C) 2014 Elsevier Ltd. All rights reserved.
引用
收藏
页码:92 / 115
页数:24
相关论文
共 50 条
  • [1] Meta-policies for distributed role-based access control systems
    Belokosztolszki, A
    Moody, K
    THIRD INTERNATION WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2002, : 106 - 115
  • [2] Managing the lifecycle of XACML delegation policies in federated environments
    Sanchez, Manuel
    Canovas, Oscar
    Lopez, Gabriel
    Gomez-Skarmeta, Antonio F.
    PROCEEDINGS OF THE IFIP TC 11/ 23RD INTERNATIONAL INFORMATION SECURITY CONFERENCE, 2008, : 717 - +
  • [3] Adaptive XACML access policies for heterogeneous distributed IoT environments
    Riad, Khaled
    Cheng, Jieren
    INFORMATION SCIENCES, 2021, 548 : 135 - 152
  • [4] Evaluating Distributed XACML Policies
    Dhankhar, Vijayant
    Kaushik, Saket
    Wijesekera, Duminda
    Nerode, Anil
    SWS'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON SECURE WEB SERVICES, 2007, : 99 - 110
  • [5] META-POLICIES FOR MEGA-GOVERNMENT
    ROSE, R
    PUBLIC INTEREST, 1984, (75) : 99 - 110
  • [6] Trust meta-policies for flexible and dynamic policy based trust management
    Quinn, Karl
    Lewis, David
    O'Sullivan, Declan
    Wade, Vincent P.
    SEVENTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2006, : 145 - +
  • [7] Extending COPS-PR with Meta-Policies for Scalable Management of IP Networks
    Boutaba R.
    Polyrakis A.
    Journal of Network and Systems Management, 2002, 10 (1) : 91 - 106
  • [8] A Semantic Approach for Managing Trust and Uncertainty in Distributed Systems Environments
    Ramparany, Fano
    Mondi, Ravi
    Demazeau, Yves
    2016 21ST INTERNATIONAL CONFERENCE ON ENGINEERING OF COMPLEX COMPUTER SYSTEMS (ICECCS 2016), 2016, : 63 - 70
  • [9] Generalists and specialists in executive politics: Why ambitious meta-policies so often fail
    Jann, Werner
    Wegrich, Kai
    PUBLIC ADMINISTRATION, 2019, 97 (04) : 845 - 860
  • [10] Managing risks in RBAC employed distributed environments
    Celikel, Ebru
    Kantarcioglu, Murat
    Thuraisingham, Bhavani
    Bertino, Elisa
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2007: COOPIS, DOA, ODBASE, GADA, AND IS, PT 2, PROCEEDINGS, 2007, 4804 : 1548 - +