• DocumentCode
    3135927
  • Title

    XACML-Based Policy-Driven Access Control for Mobile Environments

  • Author

    Qing, Xuebing ; Adams, Carlisle

  • Author_Institution
    SITE, Ottawa Univ., Ont.
  • fYear
    2006
  • fDate
    38838
  • Firstpage
    643
  • Lastpage
    646
  • Abstract
    Many applications of eXtensible Access Control Markup Language (XACML) have been found in security application solutions, yet few of them succeed in addressing authorization issues that are common in typical business and leisure scenarios that involve mobile users, such as identification management in a mobile environment, issuing a proper authorization request to a domain where the security model is unknown, locating all the applicable policies for an unknown requester, finding a proper service provider that can not compromise the requester´s data confidentiality and integrity, and the issue of applicability of reputation data. An XACML-based architecture is proposed to tackle the above issues. A subject ID mapping service is the foundation of the architecture, upon which a meta policy server (MPS) is designed to locate the policies for a requester and provide guidelines for overall security management, while reverse authorization is used to guarantee the requester´s privacy. In addition, a private reputation attribute authority (AA) handles reputation data applicability problem. A security handshake protocol for secure communication between the MPS and subject attribute authorities is also an important part of the solution. It is detailed in another paper: KEAML $Key Exchange and Authentication Markup Language
  • Keywords
    XML; authorisation; data integrity; mobile computing; network servers; telecommunication security; attribute authority; authorization; data integrity; eXtensible Access Control Markup Language; identification management; meta policy server; mobile environment; policy-driven access control; security handshake protocol; Access control; Authentication; Authorization; Data security; Environmental management; Guidelines; Identity management systems; Markup languages; Privacy; Protocols; Authorization in mobile environments; Meta Policy Server; reverse authorization; subject ID mapping;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Electrical and Computer Engineering, 2006. CCECE '06. Canadian Conference on
  • Conference_Location
    Ottawa, Ont.
  • Print_ISBN
    1-4244-0038-4
  • Electronic_ISBN
    1-4244-0038-4
  • Type

    conf

  • DOI
    10.1109/CCECE.2006.277617
  • Filename
    4054637