DocumentCode :
3283186
Title :
Conformance Checking of Access Control Policies Specified in XACML
Author :
Hu, Vincent C. ; Martin, Evan ; Hwang, JeeHyun ; Xie, Tao
Author_Institution :
Nat. Inst. of Stand. & Technol., Gaithersburg
Volume :
2
fYear :
2007
fDate :
24-27 July 2007
Firstpage :
275
Lastpage :
280
Abstract :
Access control is one of the most fundamental and widely used security mechanisms. Access control mechanisms control which principals such as users or processes have access to which resources in a system. To facilitate managing and maintaining access control, access control policies are increasingly written in specification languages such as XACML. The specification of access control policies itself is often a challenging problem. Furthermore, XACML is intentionally designed to be generic: it provides the freedom in describing access control policies, which are well-known or invented ones. But the flexibility and expressiveness provided by XACML come at the cost of complexity, verbosity, and lack of desirable-property enforcement. Often common properties for specific access control policies may not be satisfied when these policies are specified in XACML, causing the discrepancy between what the policy authors intend to specify and what the actually specified XACML policies reflect. In this position paper, we propose an approach for conducting conformance checking of access control policies specified in XACML based on existing verification and testing tools for XACML policies.
Keywords :
XML; authorisation; conformance testing; formal verification; specification languages; XACML policies; access control; conformance checking; security mechanism; specification language; Access control; Computer science; Control systems; Costs; Markup languages; NIST; Software standards; Specification languages; Standards organizations; Testing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Software and Applications Conference, 2007. COMPSAC 2007. 31st Annual International
Conference_Location :
Beijing
ISSN :
0730-3157
Print_ISBN :
0-7695-2870-8
Type :
conf
DOI :
10.1109/COMPSAC.2007.96
Filename :
4291136
Link To Document :
بازگشت