DocumentCode :
2415812
Title :
How to Declare Access Control Policies for XML Structured Information Objects using OASIS´ eXtensible Access Control Markup Language (XACML)
Author :
Matheus, Andreas
Author_Institution :
Technische Universität München, Munich, Germany
fYear :
2005
fDate :
03-06 Jan. 2005
Abstract :
Web Services, as the new building blocks of today´s Internet provide the power to access distributed and heterogeneous information objects, which is the base for more advanced use like in electronic commerce. But, the access to these information objects is not always unrestricted. The owner of the information objects may control access due to different reasons. This paper introduces a novel approach for declaring information object related access restrictions, based on a valid XML encoding. The paper shows, how the access restrictions can be declared using XACML and Xpath. Based on the specified ´fine grained´ policies, multiple policies can be applicable. If these policies declare positive and negative permissions for the same subject, policy inconsistencies exist. The paper also focuses on specifying the ground of policy inconsistencies and how to solve them.
Keywords :
Access control; Electronic commerce; Encoding; HTML; Markup languages; Permission; Simple object access protocol; Web and internet services; Web services; XML;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
System Sciences, 2005. HICSS '05. Proceedings of the 38th Annual Hawaii International Conference on
ISSN :
1530-1605
Print_ISBN :
0-7695-2268-8
Type :
conf
DOI :
10.1109/HICSS.2005.300
Filename :
1385573
Link To Document :
بازگشت