DocumentCode :
1799964
Title :
Towards efficient evaluation of XACML policies
Author :
Mourad, Alain ; Jebbaoui, Hussein
Author_Institution :
Dept. of Comput. Sci. & Math., Lebanese American Univ., Beirut, Lebanon
fYear :
2014
fDate :
23-24 July 2014
Firstpage :
164
Lastpage :
171
Abstract :
Policy-based computing is taking an increasing role in providing real-time decisions and governing the systematic interaction among distributed cloud and Web services. XACML has been known as the de facto standard widely used by many vendors for specifying access control and context-aware policies. Accordingly, the size and complexity of XACML policies are significantly growing to cope with the evolution of web-based applications. This growth raised many concerns related to the efficiency of real-time decision process (i.e. policy evaluation). This paper is addressing this concern through the elaboration of SBA-XACML, a novel set-based algebra scheme that provides efficient evaluation of XACML policies. Our approach constitutes of elaborating (1) set-based language that covers all the XACML components and establish an intermediate layer to which policies are automatically converted, and (2) policy evaluation module that provides better performance compared to the industrial standard Sun Policy Decision Point (PDP) and its corresponding ameliorations. Experiments have been conducted on real-life and synthetic XACML policies in order to demonstrate the efficiency, relevance and scalability of our proposition. The experimental results explore that SBA-XACML evaluation of large and small sizes policies offers better performance than the current approaches, by a factor ranging between 2.4 and 15 times faster depending on policy size.
Keywords :
Internet; algebra; authorisation; formal specification; SBA-XACML evaluation; Web services; Web-based applications; XACML policies; access control specification; context-aware policy specification; de facto standard; distributed cloud; policy evaluation module; policy-based computing; real-time decision process; set-based algebra scheme; set-based language; systematic interaction; Access control; Algebra; Semantics; Standards; Sun; Syntactics; Access Control; Policy Evaluation; Real-Time Decision; Set-Based Algebra; Web Services Security; XACML;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Privacy, Security and Trust (PST), 2014 Twelfth Annual International Conference on
Conference_Location :
Toronto, ON
Print_ISBN :
978-1-4799-3502-4
Type :
conf
DOI :
10.1109/PST.2014.6890936
Filename :
6890936
Link To Document :
بازگشت