DocumentCode
3135927
Title
XACML-Based Policy-Driven Access Control for Mobile Environments
Author
Qing, Xuebing ; Adams, Carlisle
Author_Institution
SITE, Ottawa Univ., Ont.
fYear
2006
fDate
38838
Firstpage
643
Lastpage
646
Abstract
Many applications of eXtensible Access Control Markup Language (XACML) have been found in security application solutions, yet few of them succeed in addressing authorization issues that are common in typical business and leisure scenarios that involve mobile users, such as identification management in a mobile environment, issuing a proper authorization request to a domain where the security model is unknown, locating all the applicable policies for an unknown requester, finding a proper service provider that can not compromise the requester´s data confidentiality and integrity, and the issue of applicability of reputation data. An XACML-based architecture is proposed to tackle the above issues. A subject ID mapping service is the foundation of the architecture, upon which a meta policy server (MPS) is designed to locate the policies for a requester and provide guidelines for overall security management, while reverse authorization is used to guarantee the requester´s privacy. In addition, a private reputation attribute authority (AA) handles reputation data applicability problem. A security handshake protocol for secure communication between the MPS and subject attribute authorities is also an important part of the solution. It is detailed in another paper: KEAML $Key Exchange and Authentication Markup Language
Keywords
XML; authorisation; data integrity; mobile computing; network servers; telecommunication security; attribute authority; authorization; data integrity; eXtensible Access Control Markup Language; identification management; meta policy server; mobile environment; policy-driven access control; security handshake protocol; Access control; Authentication; Authorization; Data security; Environmental management; Guidelines; Identity management systems; Markup languages; Privacy; Protocols; Authorization in mobile environments; Meta Policy Server; reverse authorization; subject ID mapping;
fLanguage
English
Publisher
ieee
Conference_Titel
Electrical and Computer Engineering, 2006. CCECE '06. Canadian Conference on
Conference_Location
Ottawa, Ont.
Print_ISBN
1-4244-0038-4
Electronic_ISBN
1-4244-0038-4
Type
conf
DOI
10.1109/CCECE.2006.277617
Filename
4054637
Link To Document