A Proposal on Enhancing XACML with Continuous Usage Control Features

被引:25
作者
Colombo, Maurizio [1 ]
Lazouski, Aliaksandr [2 ]
Martinelli, Fabio [1 ]
Mori, Paolo [1 ]
机构
[1] CNR, Ist Informat & Telemat, Via G Moruzzi 1, I-56100 Pisa, Italy
[2] Univ Pisa, I-56100 Pisa, Italy
来源
GRIDS, P2P AND SERVICES COMPUTING | 2010年
关键词
Access control; usage control; policy language; XACML; UCON; Grid computing;
D O I
10.1007/978-1-4419-6794-7_11
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Usage control (UCON) proposed by R. Sandhu et al. [8, 9] is an attribute-based authorization model and its main novelties are mutability of attributes and continuity of control. OASIS eXtensible Access Control Markup Language (XACML) [10] is a widely-used language to write authorization policies to protect resources in a distributed computing environment (e.g. Grid). The XACML policy specifies before-usage authorization process optionally complemented with obligation actions fulfillment. By now, XACML has insufficient facilities to express continuous usage control afterwards an access was granted and started. In this paper, we introduce U-XACML, a new policy language, which enhances the original XACML with the UCON novelties. We extend a syntax and semantics of the XACML policy to define mutability of attributes and continuity of control. We introduce an architecture to enforce the U-XACML policy.
引用
收藏
页码:133 / +
页数:2
相关论文
共 11 条
[1]  
COLOMBO M, 2009, 2009 IEEE INT WORKSH
[2]  
DAMIANI ML, 2008, FTDCS 08, P199
[3]  
FENG J, 2007, IEEE ACM INT WORKSH, P66
[4]  
Hafner M, 2008, LECT NOTES COMPUT SC, V5002, P132
[5]  
Katt B, 2008, SACMAT'08: PROCEEDINGS OF THE 13TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, P123
[6]  
MARTINELLI F, 2005, P INT C AUT AUT SYST, P82
[7]  
NAQVI S, 2008, SERVICEWAVE 08, P242
[8]  
Park J., 2004, ACM Transactions on Information and Systems Security, V7, P128, DOI 10.1145/984334.984339
[9]  
PARK J, 2002, SACMAT 02, P57, DOI DOI 10.1145/507711.507722
[10]  
[张新娟 ZHANG Xinjuan], 2008, [扬州大学学报. 自然科学版, Journal of Yangzhou University], V11, P1