Policy Evaluation and Dynamic Management Based on Matching Tree for XACML

被引:4
|
作者
Kang, Hongzhaoning [1 ]
Gang, Liu [1 ]
Wang, Quan [1 ]
Zhang, Runnan [1 ]
Zhong, Zichao [1 ]
Tian, Yumin [1 ]
机构
[1] XIDIAN Univ, Comp Sci & Technol, Xian, Peoples R China
关键词
XACML; access control policy; matching tree; dynamic management; DISTRIBUTED ENVIRONMENTS; ACCESS-CONTROL;
D O I
10.1109/TrustCom50675.2020.00209
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
As a widely recognized policy language of access control, the eXtensible Access Control Markup Language (XACML) is widely used with its fine-grained and easy-to-read. With the application of XACML, researchers find that the XACML based policy evaluation and policy management methods can no longer meet the current large-scale requests for efficient access and dynamic management requirements. To improve the performance of policy evaluation based on XACML, we propose a policy evaluation method based on the matching tree to search policy efficiently and avoid the extra consumption of invalid policy participation. Furthermore, we propose a policy dynamic management method based on the matching tree to reduce the scale of the policy to be disabled for management, by adding locks in the tree node and the information mapping table. Through theoretical derivation and the factors that may affect its evaluation performance, we verify the improvement of evaluation efficiency. The simulation also shows the improvement of the evaluation engine based on the matching tree compared with OpenAz.
引用
收藏
页码:1530 / 1535
页数:6
相关论文
共 50 条
  • [41] A KD-TREE BASED DYNAMIC INDEXING SCHEME FOR VIDEO RETRIEVAL AND GEOMETRY MATCHING
    Gao, Li
    Li, Zhu
    Katsaggelos, Aggelos K.
    2008 PROCEEDINGS OF 17TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, VOLS 1 AND 2, 2008, : 940 - +
  • [42] Tree matching for evaluation of speech interpretation systems
    Thomae, M
    Fabian, T
    Lieb, R
    Ruske, G
    ASRU'03: 2003 IEEE WORKSHOP ON AUTOMATIC SPEECH RECOGNITION AND UNDERSTANDING ASRU '03, 2003, : 477 - 482
  • [43] Improved Appearance-Based Matching in Similar and Dynamic Environments using a Vocabulary Tree
    Sabatta, Deon
    Scaramuzza, Davide
    Siegwart, Roland
    2010 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION (ICRA), 2010, : 1008 - 1013
  • [44] Secret Handshakes with Dynamic Expressive Matching Policy
    Hou, Lin
    Lai, Junzuo
    Liu, Lixian
    INFORMATION SECURITY AND PRIVACY, PT I, 2016, 9722 : 461 - 476
  • [45] A New Testing Method for XACML 3.0 Policy Based on ABAC and Data Flow
    Zhang, Yunpeng
    Zhang, Beibei
    2017 13TH IEEE INTERNATIONAL CONFERENCE ON CONTROL & AUTOMATION (ICCA), 2017, : 160 - 164
  • [46] Dynamic tree routing under the "matching with consumption" model
    Pantziou, GE
    Roberts, A
    Symvonis, A
    ALGORITHMS AND COMPUTATION, 1996, 1178 : 275 - 284
  • [47] System Message Based Predict Policy for Dynamic Power Management
    Ma, Xi-Qiang
    Yang, Fang
    Li, Ji-Shun
    Xue, Yu-Jun
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATION AND SENSOR NETWORKS (WCSN 2016), 2016, 44 : 580 - 584
  • [48] Dynamic Policy based Network Management Scheme in Mobile Environment
    Liu, Xue-jie
    Liu, Yan-heng
    Wei, Da
    Liu, Hu-ying
    ISCSCT 2008: INTERNATIONAL SYMPOSIUM ON COMPUTER SCIENCE AND COMPUTATIONAL TECHNOLOGY, VOL 1, PROCEEDINGS, 2008, : 434 - 437
  • [49] Dynamic generation of activity plan for policy-based management
    Chen, S
    Poo, GS
    2004 12TH IEEE INTERNATIONAL CONFERENCE ON NETWORKS, VOLS 1 AND 2 , PROCEEDINGS: UNITY IN DIVERSITY, 2004, : 114 - 118
  • [50] Dynamic conflict detection in policy-based management systems
    Dunlop, N
    Indulska, J
    Raymond, K
    SIXTH INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE, PROCEEDINGS, 2002, : 15 - 26