DocumentCode
2986742
Title
Toward Self-Contained Authorization Policies
Author
Laborde, Romain ; Cheaito, Marwan ; Barrère, François ; Benzekri, Abdelmalek
Author_Institution
IRIT/SIERA, Univ. Paul Sabatier, Toulouse, France
fYear
2010
fDate
21-23 July 2010
Firstpage
103
Lastpage
106
Abstract
One of the key motivations of policy-based management is flexibility and adaptability to existing infrastructure and change management. In the context of security, modern policy languages such as XACML are extensible and support natively the expression of new information and manipulation operations. However, policy engines, which evaluate users´ requests according to policies, may not support this new policy information. As a consequence, policy writers have to verify whether the target policy engine can execute his/her policy or not when (s)he writes it. In this article, we introduce the concept of self-contained policy to solve this deployment issue. A self-contained policy includes all the necessary information required by a policy engine to execute a policy. We propose a service component based architecture to support self-contained policies.
Keywords
authorisation; management of change; object-oriented programming; software management; XACML; change management; policy engines; policy languages; policy-based management; self-contained authorization policies; self-contained policy; service component based architecture; Authorization; Context; Engines; Geometry; Organizations; XACML; attribute based access control; policy deployment; self-contained policy;
fLanguage
English
Publisher
ieee
Conference_Titel
Policies for Distributed Systems and Networks (POLICY), 2010 IEEE International Symposium on
Conference_Location
Fairfax, VA
Print_ISBN
978-1-4244-8206-1
Electronic_ISBN
978-0-7695-4238-6
Type
conf
DOI
10.1109/POLICY.2010.18
Filename
5630212
Link To Document