Title :
Realization of FGAC model using XACML policy specification
Author :
Shibli, Muhammad Awais ; Masood, Rahat ; Habiba, Umme
Author_Institution :
Sch. of Electr. Eng. & Comput. Sci. (SEECS), Nat. Univ. of Sci. & Technol. (NUST), Islamabad, Pakistan
Abstract :
FGAC model has been adopted by enterprise applications, for the protection of their databases. Most of these deployments are not only limited in purpose but are dependent upon various other factors including query modification algorithms and software development languages. These factors have not only limited their applicability for distributed computing environments but have also affected their widespread adoption and acceptance. Moreover, due to the absence of standard FGAC profile specification, existing FGAC authorization techniques become unsuitable for advance applications such as Web 2.0 and cannot be deployed across various platforms, thus fall short of flexibility and customizability. As a result, there is an increasing demand for standard based FGAC specification that could be easily fit into majority of computing environments. In this paper, we bring forth a policy specification (profile) for FGAC model. Our proposed specification is not restricted to database applications only; rather it is generic and flexible enough to be applied on every type of application. It explicates the ways in which organizations would be able to implement standard based fine-grained access control for nearly every application. We present the case-study - a realization of FGAC model based on the proposed policy specification followed by a complete dryrun of policy evaluation procedure.
Keywords :
XML; authorisation; business data processing; data protection; query processing; FGAC authorization techniques; FGAC model realization; Web 2.0; XACML policy specification; computing environments; database protection; distributed computing environments; enterprise applications; policy evaluation procedure; query modification algorithms; software development languages; standard FGAC profile specification; standard based fine-grained access control; Access control; Computational modeling; Databases; Organizations; Standards organizations; Authorization; Fine-Grained Access Control; Policy Administration Point; Policy Decision Point; Policy Specification Language; eXtensible Access Control Markup Language;
Conference_Titel :
Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD), 2015 16th IEEE/ACIS International Conference on
Conference_Location :
Takamatsu
DOI :
10.1109/SNPD.2015.7176199