Policy Evaluation and Dynamic Management Based on Matching Tree for XACML

被引:4
|
作者
Kang, Hongzhaoning [1 ]
Gang, Liu [1 ]
Wang, Quan [1 ]
Zhang, Runnan [1 ]
Zhong, Zichao [1 ]
Tian, Yumin [1 ]
机构
[1] XIDIAN Univ, Comp Sci & Technol, Xian, Peoples R China
关键词
XACML; access control policy; matching tree; dynamic management; DISTRIBUTED ENVIRONMENTS; ACCESS-CONTROL;
D O I
10.1109/TrustCom50675.2020.00209
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
As a widely recognized policy language of access control, the eXtensible Access Control Markup Language (XACML) is widely used with its fine-grained and easy-to-read. With the application of XACML, researchers find that the XACML based policy evaluation and policy management methods can no longer meet the current large-scale requests for efficient access and dynamic management requirements. To improve the performance of policy evaluation based on XACML, we propose a policy evaluation method based on the matching tree to search policy efficiently and avoid the extra consumption of invalid policy participation. Furthermore, we propose a policy dynamic management method based on the matching tree to reduce the scale of the policy to be disabled for management, by adding locks in the tree node and the information mapping table. Through theoretical derivation and the factors that may affect its evaluation performance, we verify the improvement of evaluation efficiency. The simulation also shows the improvement of the evaluation engine based on the matching tree compared with OpenAz.
引用
收藏
页码:1530 / 1535
页数:6
相关论文
共 50 条
  • [1] XACML Policy Evaluation with Dynamic Context Handling
    Ammar, Nariman
    Malik, Zaki
    Bertino, Elisa
    Rezgui, Abdelmounaam
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2015, 27 (09) : 2575 - 2588
  • [2] An efficient policy evaluation engine for XACML policy management
    Deng, Fan
    Yu, Zhenhua
    Liu, Wenjing
    Luo, Xiaoqing
    Fu, Yu
    Qiang, Ben
    Xu, Chaoyang
    Li, Zhiwu
    INFORMATION SCIENCES, 2021, 547 : 1105 - 1121
  • [3] XACML Policy Evaluation with Dynamic Context Handling
    Ammar, Nariman
    Malik, Zaki
    Rezgui, Abdelmounaam
    Bertino, Elisa
    2016 32ND IEEE INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE), 2016, : 1570 - 1571
  • [4] Decision Diagrams for XACML Policy Evaluation and Management
    Canh Ngo
    Demchenko, Yuri
    de Laat, Cees
    COMPUTERS & SECURITY, 2015, 49 : 1 - 16
  • [5] Clustering and supervised response for XACML policy evaluation and management
    Deng, Fan
    Yu, Zhenhua
    Zhang, Liyong
    Ge, Xiaodong
    Zhao, Ruiyu
    Li, Xiaotong
    Ma, Yuhao
    Yan, Yang
    Wen, Zhe
    KNOWLEDGE-BASED SYSTEMS, 2020, 205 (205)
  • [6] An ACO-based Algorithm for Efficient XACML Policy Evaluation
    Zhang, Yunpeng
    Zhang, Beibei
    PROCEEDINGS OF THE 2017 2ND INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION AND ARTIFICIAL INTELLIGENCE (CAAI 2017), 2017, 134 : 282 - 288
  • [7] \ Statistics & Clustering Based Framework for Efficient XACML Policy Evaluation
    Marouf, Said
    Shehab, Mohamed
    Squicciarini, Anna
    Sundareswaran, Smitha
    2009 IEEE INTERNATIONAL SYMPOSIUM ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, 2009, : 118 - +
  • [8] Policy Conflict Management using XACML
    Shamoon, Imran
    Rajpoot, Qasim
    Shibli, Awais
    2012 8TH INTERNATIONAL CONFERENCE ON COMPUTING AND NETWORKING TECHNOLOGY (ICCNT, INC, ICCIS AND ICMIC), 2012, : 287 - 291
  • [9] Access control policy management based on extended-XACML
    State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Sciences, Beijing 100080, China
    Tongxin Xuebao, 2007, 1 (103-110):
  • [10] An XACML-based policy management and authorization service for globus resources
    Lorch, M
    Kafura, D
    Shah, S
    FOURTH INTERNATIONAL WORKSHOP ON GRID COMPUTING, PROCEEDINGS, 2003, : 208 - 210