• DocumentCode
    2693223
  • Title

    Dynamic obligation specification and negotiation

  • Author

    Lischka, Mario

  • Author_Institution
    NEC Labs. Eur., NEC Eur. Ltd., Heidelberg, Germany
  • fYear
    2010
  • fDate
    19-23 April 2010
  • Firstpage
    155
  • Lastpage
    162
  • Abstract
    OASIS XACML has become a recognized standard for the specification of access control policies, and has specified a generic framework for access control. While the XACML policy language is very flexible for access privileges, there is currently no method to specify the obligations send from a policy decision point (PDP) to a policy enforcement point (PEP) in a generic way. Potential conflicts between obligations are not even considered in the language specification, thus no generic detection of these conflicts is possible. But this becomes an important aspect in a distributed environment like SaaS, in which the policies and their enforcement are not coordinated by a single entity. In this paper we will present a dynamic obligation specification language which covers the following aspects. First, it allows us to define the actual obligation and its parameters including the relationship, especially conflicts among them. Second, the negotiation of the supported obligation between distributed PDP and PEP is introduced. Third, potential conflicts are detected and partially solved at runtime based on the definition of the obligations. We show how the introduced extensible obligation markup language (XOML) could be integrated into the XACML standard.
  • Keywords
    XML; access control; authorisation; OASIS XACML; access control policies; dynamic obligation specification language; extensible obligation markup language; policy decision point; policy enforcement point; Access control; Cryptography; Data privacy; Decoding; Europe; Laboratories; Markup languages; National electric code; Runtime; Specification languages;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Operations and Management Symposium (NOMS), 2010 IEEE
  • Conference_Location
    Osaka
  • ISSN
    1542-1201
  • Print_ISBN
    978-1-4244-5366-5
  • Electronic_ISBN
    1542-1201
  • Type

    conf

  • DOI
    10.1109/NOMS.2010.5488453
  • Filename
    5488453