• DocumentCode
    2207247
  • Title

    Decentralized XACML Overlay Network

  • Author

    Alzahrani, Ali ; Janicke, Helge ; Abubaker, Sarshad

  • Author_Institution
    Software Technol. Res. Lab., De Montfort Univ., Leicester, UK
  • fYear
    2010
  • fDate
    June 29 2010-July 1 2010
  • Firstpage
    1032
  • Lastpage
    1037
  • Abstract
    We propose a novel approach for the collaborative enforcement of security policies in distributed systems that is based on the dynamic (re-) deployment of multiple PDPs. The policies enforced by the collaborating PDPs are analysed and decomposed from a system wide policy as present in current centralized approaches. The security policy is decomposed into sub-policies based on an object domain approach so the decisions are local to the object´s domain. The classes of policies investigated are dynamic history-based access control policies, ie. the PDPs decision is dependent on the history of interaction between users and system resources. This type of policy can capture static and dynamic separation of duty policies, as are commonly found in commercial organisations. The distribution model of the PDP allows for the coordination and synchronisation of PDPs on the basis of events, where a decision is based on a previous history originating from other PDPs. The key contribution of this paper is the analysis of temporal dependencies between policies and an efficient PDP distribution strategy for object-based distributed systems as well as presenting a designed library that create and synchronize a network of PDP´s in a peer to peer fashion.
  • Keywords
    XML; authorisation; distributed processing; groupware; collaborative policy enforcement; decentralized XACML overlay network; dynamic history-based access control; multiple PDP; object domain approach; object-based distributed system; security policy; Access control; Decision making; History; Libraries; Prototypes; Synchronization; PDPs coordination; collaborative policy enforcement; decentralised policy enforcement;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer and Information Technology (CIT), 2010 IEEE 10th International Conference on
  • Conference_Location
    Bradford
  • Print_ISBN
    978-1-4244-7547-6
  • Type

    conf

  • DOI
    10.1109/CIT.2010.189
  • Filename
    5578621