Managing XACML systems in distributed environments through Meta-Policies

被引:13
|
作者
Diaz-Lopez, Daniel [1 ]
Dolera-Tormo, Gines [1 ]
Gomez-Marmol, Felix [2 ]
Martinez-Perez, Gregorio [1 ]
机构
[1] Univ Murcia, Dept Ingn Informac & Comun, E-30100 Murcia, Spain
[2] NEC Labs Europe, D-69115 Heidelberg, Germany
关键词
XACML; Access control system; Distributed environments; SAML; Access control policy; Policy management;
D O I
10.1016/j.cose.2014.10.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Policy-based authorization systems have been largely deployed nowadays to control different privileges over a big amount of resources within a security domain. With policies it is possible to reach a fine-grained level of expressiveness to state proper responses of a system against multiple access control requests. In this context, XACML has achieved a big popularity between both industry and academy as a standard for the definition of access control policies, as well as an architecture for the evaluation of authorization requests and for the issuing of authorization decisions. However, the applicability of XACML is still not clear in collaborative and distributed environments composed of several security domains sharing the access control over some specific resources. Such a circumstance manifests when many security domains can simultaneously define the behavior that a resource will have upon received authorization requests, like for instance an organization with many subsidiaries, a company with a service virtualization business model, etc. In this paper we propose a solution to reach an effective distributed policy management considering that a number of policies in one domain may be confidential. To this end, the default XACML architecture has been redefined in order to use i) Master and Slave PAPs to communicate security domains, ii) Meta-Policies, to define privileges over access control policies (the policies become the managed resources) and iii) SAML extensions to protect the policy management messages which flow between security domains. The experiments and the defined scenarios in the paper prove the validity of the proposed solution. (C) 2014 Elsevier Ltd. All rights reserved.
引用
收藏
页码:92 / 115
页数:24
相关论文
共 50 条
  • [21] Meta-modeling for distributed object environments
    Atkinson, C
    FIRST INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING WORKSHOP, PROCEEDINGS, 1997, : 90 - 101
  • [22] A discussion of distributed system environments and distributed operating systems
    Jia, X
    Cao, J
    Jia, W
    Lee, CH
    PARALLEL AND DISTRIBUTED COMPUTING SYSTEMS - PROCEEDINGS OF THE ISCA 9TH INTERNATIONAL CONFERENCE, VOLS I AND II, 1996, : 37 - 42
  • [23] Managing distributed systems using OSI systems management
    Chadha, R
    Wuu, SY
    PROCEEDINGS OF THE IEEE SECOND INTERNATIONAL WORKSHOP ON SYSTEMS MANAGEMENT, 1996, : 117 - 126
  • [24] Managing personal health information in distributed research network environments
    Christine E Bredfeldt
    Amy L Butani
    Roy Pardee
    Paul Hitz
    Sandy Padmanabhan
    Gwyn Saylor
    BMC Medical Informatics and Decision Making, 13
  • [25] Managing personal health information in distributed research network environments
    Bredfeldt, Christine E.
    Butani, Amy L.
    Pardee, Roy
    Hitz, Paul
    Padmanabhan, Sandy
    Saylor, Gwyn
    BMC MEDICAL INFORMATICS AND DECISION MAKING, 2013, 13
  • [26] Security architecture for a systematic administration of SELinux policies in distributed environments
    Chavez Lugo, Pedro
    Flores, Juan J.
    Garcia Garcia, Juan Manuel
    PROCEEDINGS OF THE 7TH WSEAS INTERNATIONAL CONFERENCE ON DATA NETWORKS, COMMUNICATIONS, COMPUTERS (DNCOCO '08): RECENT ADVANCES IN DATA NETWORKS, COMMUNICATIONS, COMPUTERS, 2008, : 136 - +
  • [27] Financial evaluation of Participating Life Insurance Policies in distributed environments
    Corsaro, Stefania
    De Angelis, Pasquale Luigi
    Marino, Zelda
    Perla, Francesca
    Zanetti, Paolo
    2008 IEEE INTERNATIONAL SYMPOSIUM ON PARALLEL & DISTRIBUTED PROCESSING, VOLS 1-8, 2008, : 2905 - 2912
  • [28] DSA - AN ARCHITECTURE FOR DISTRIBUTED SYSTEMS ENVIRONMENTS
    YON, G
    COMPUTER NETWORKS AND ISDN SYSTEMS, 1982, 6 (05): : 361 - 361
  • [29] Distributed collaborative environments for systems engineering
    McQuay, WK
    IEEE AEROSPACE AND ELECTRONIC SYSTEMS MAGAZINE, 2005, 20 (08) : 7 - 12
  • [30] Reengineering legacy systems for distributed environments
    Serrano, MA
    Carver, DL
    de Oca, CM
    JOURNAL OF SYSTEMS AND SOFTWARE, 2002, 64 (01) : 37 - 55