• DocumentCode
    3429297
  • Title

    Obligation policies: an enforcement platform

  • Author

    Gama, Pedro ; Ferreira, Paulo

  • Author_Institution
    Distributed Syst. Group, INESC-ID/IST, Lisboa, Portugal
  • fYear
    2005
  • fDate
    6-8 June 2005
  • Firstpage
    203
  • Lastpage
    212
  • Abstract
    The use of policy-based mechanisms significantly reduces the complexity associated with application development and operation. In particular, history-based policies allow the system to base application access decisions on the evaluation of other actions executed in the past. Obligation-based policies enhance this concept with the possibility of enforcing that certain actions will be executed in the future. This is a necessary evolution because some semantics are either easier to express as obligations or cannot be specified using traditional authorization mechanisms. Currently, the absence of enforcement mechanisms for obligation-based policies imposes the implementation of ad-hoc functional constraints. This increases development time and introduces security vulnerabilities into the policy engine. We present a policy platform called Heimdall, which supports the definition and enforcement of obligation-based policies. A prototype implementation is described, together with an evaluation which denotes encouraging results.
  • Keywords
    authorisation; Heimdall; ad hoc functional constraint; application development; authorization mechanism; enforcement platform; history-based policies; obligation policies; security vulnerabilities; Authorization; Conferences; Control systems; Engines; Prototypes; Quality of service; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Policies for Distributed Systems and Networks, 2005. Sixth IEEE International Workshop on
  • Print_ISBN
    0-7695-2265-3
  • Type

    conf

  • DOI
    10.1109/POLICY.2005.18
  • Filename
    1454319