• DocumentCode
    2986742
  • Title

    Toward Self-Contained Authorization Policies

  • Author

    Laborde, Romain ; Cheaito, Marwan ; Barrère, François ; Benzekri, Abdelmalek

  • Author_Institution
    IRIT/SIERA, Univ. Paul Sabatier, Toulouse, France
  • fYear
    2010
  • fDate
    21-23 July 2010
  • Firstpage
    103
  • Lastpage
    106
  • Abstract
    One of the key motivations of policy-based management is flexibility and adaptability to existing infrastructure and change management. In the context of security, modern policy languages such as XACML are extensible and support natively the expression of new information and manipulation operations. However, policy engines, which evaluate users´ requests according to policies, may not support this new policy information. As a consequence, policy writers have to verify whether the target policy engine can execute his/her policy or not when (s)he writes it. In this article, we introduce the concept of self-contained policy to solve this deployment issue. A self-contained policy includes all the necessary information required by a policy engine to execute a policy. We propose a service component based architecture to support self-contained policies.
  • Keywords
    authorisation; management of change; object-oriented programming; software management; XACML; change management; policy engines; policy languages; policy-based management; self-contained authorization policies; self-contained policy; service component based architecture; Authorization; Context; Engines; Geometry; Organizations; XACML; attribute based access control; policy deployment; self-contained policy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Policies for Distributed Systems and Networks (POLICY), 2010 IEEE International Symposium on
  • Conference_Location
    Fairfax, VA
  • Print_ISBN
    978-1-4244-8206-1
  • Electronic_ISBN
    978-0-7695-4238-6
  • Type

    conf

  • DOI
    10.1109/POLICY.2010.18
  • Filename
    5630212