DocumentCode
2207247
Title
Decentralized XACML Overlay Network
Author
Alzahrani, Ali ; Janicke, Helge ; Abubaker, Sarshad
Author_Institution
Software Technol. Res. Lab., De Montfort Univ., Leicester, UK
fYear
2010
fDate
June 29 2010-July 1 2010
Firstpage
1032
Lastpage
1037
Abstract
We propose a novel approach for the collaborative enforcement of security policies in distributed systems that is based on the dynamic (re-) deployment of multiple PDPs. The policies enforced by the collaborating PDPs are analysed and decomposed from a system wide policy as present in current centralized approaches. The security policy is decomposed into sub-policies based on an object domain approach so the decisions are local to the object´s domain. The classes of policies investigated are dynamic history-based access control policies, ie. the PDPs decision is dependent on the history of interaction between users and system resources. This type of policy can capture static and dynamic separation of duty policies, as are commonly found in commercial organisations. The distribution model of the PDP allows for the coordination and synchronisation of PDPs on the basis of events, where a decision is based on a previous history originating from other PDPs. The key contribution of this paper is the analysis of temporal dependencies between policies and an efficient PDP distribution strategy for object-based distributed systems as well as presenting a designed library that create and synchronize a network of PDP´s in a peer to peer fashion.
Keywords
XML; authorisation; distributed processing; groupware; collaborative policy enforcement; decentralized XACML overlay network; dynamic history-based access control; multiple PDP; object domain approach; object-based distributed system; security policy; Access control; Decision making; History; Libraries; Prototypes; Synchronization; PDPs coordination; collaborative policy enforcement; decentralised policy enforcement;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer and Information Technology (CIT), 2010 IEEE 10th International Conference on
Conference_Location
Bradford
Print_ISBN
978-1-4244-7547-6
Type
conf
DOI
10.1109/CIT.2010.189
Filename
5578621
Link To Document