Policy Evaluation and Dynamic Management Based on Matching Tree for XACML

被引:4
|
作者
Kang, Hongzhaoning [1 ]
Gang, Liu [1 ]
Wang, Quan [1 ]
Zhang, Runnan [1 ]
Zhong, Zichao [1 ]
Tian, Yumin [1 ]
机构
[1] XIDIAN Univ, Comp Sci & Technol, Xian, Peoples R China
关键词
XACML; access control policy; matching tree; dynamic management; DISTRIBUTED ENVIRONMENTS; ACCESS-CONTROL;
D O I
10.1109/TrustCom50675.2020.00209
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
As a widely recognized policy language of access control, the eXtensible Access Control Markup Language (XACML) is widely used with its fine-grained and easy-to-read. With the application of XACML, researchers find that the XACML based policy evaluation and policy management methods can no longer meet the current large-scale requests for efficient access and dynamic management requirements. To improve the performance of policy evaluation based on XACML, we propose a policy evaluation method based on the matching tree to search policy efficiently and avoid the extra consumption of invalid policy participation. Furthermore, we propose a policy dynamic management method based on the matching tree to reduce the scale of the policy to be disabled for management, by adding locks in the tree node and the information mapping table. Through theoretical derivation and the factors that may affect its evaluation performance, we verify the improvement of evaluation efficiency. The simulation also shows the improvement of the evaluation engine based on the matching tree compared with OpenAz.
引用
收藏
页码:1530 / 1535
页数:6
相关论文
共 50 条
  • [31] On-line tracing of XACML-based policy coverage criteria
    Lonetti, Francesca
    Marchetti, Eda
    IET SOFTWARE, 2018, 12 (06) : 480 - 488
  • [32] Distributed Access Control Management - A XACML-Based Approach
    Rissanen, Erik
    Brossard, David
    Slabbert, Adriaan
    SERVICE-ORIENTED COMPUTING - ICSOC 2009, PROCEEDINGS, 2009, 5900 : 639 - +
  • [33] An Evaluation Model for Degree of Topic Relatedness Based on Dynamic Matching
    Yu, Bin
    Zhang, Tianguang
    ECBI: 2009 INTERNATIONAL CONFERENCE ON ELECTRONIC COMMERCE AND BUSINESS INTELLIGENCE, PROCEEDINGS, 2009, : 479 - 482
  • [34] Poliseek: A Fast XACML Policy Evaluation Engine Using Dimensionality Reduction and Characterized Search
    Deng, Fan
    Yu, Zhenhua
    Zhan, Xinrui
    Wang, Chongyu
    Zhang, Xiaolin
    Zhang, Yangyang
    Qin, Zilu
    MATHEMATICS, 2022, 10 (23)
  • [35] Enforcement of U-XACML History-Based Usage Control Policy
    Martinelli, Fabio
    Matteucci, Ilaria
    Mori, Paolo
    Saracino, Andrea
    SECURITY AND TRUST MANAGEMENT, STM 2016, 2016, 9871 : 64 - 81
  • [36] EMERS: a tree matching–based performance evaluation of mathematical expression recognition systems
    Kunal Sain
    Abhishek Dasgupta
    Utpal Garain
    International Journal on Document Analysis and Recognition (IJDAR), 2011, 14 : 75 - 85
  • [37] XACML-based policy-driven access control for mobile environments
    Qing, Xuebing
    Adams, Carlisle
    2006 CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, VOLS 1-5, 2006, : 523 - +
  • [38] XACML-Based Fine-Grained Security Policy for Distributed System
    Zhang, Ai-Juan
    Gao, Jing-Xiang
    Ji, Cheng
    ADVANCED RESEARCH ON AUTOMATION, COMMUNICATION, ARCHITECTONICS AND MATERIALS, PTS 1 AND 2, 2011, 225-226 (1-2): : 848 - +
  • [39] Minimum spanning tree dynamic programming stereo-matching method based on superpixels
    Wang, Jingxue
    Xu, Zhenghui
    PHOTOGRAMMETRIC RECORD, 2023, 38 (181): : 63 - 80
  • [40] Performance evaluation of dynamic tree-based reliable multicast
    Wan, ZW
    Kadoch, M
    Elhakeem, A
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2005, E88B (05) : 2035 - 2045