• DocumentCode
    182011
  • Title

    Challenges of Composing XACML Policies

  • Author

    Stepien, Bernard ; Felty, Amy ; Matwin, S.

  • Author_Institution
    Sch. of Inf. Technol. & Eng., Univ. of Ottawa, Ottawa, ON, Canada
  • fYear
    2014
  • fDate
    8-12 Sept. 2014
  • Firstpage
    234
  • Lastpage
    241
  • Abstract
    XACML (extensible Access Control Mark-up Language) is a declarative access control policy language that has unique language constructs for factoring out access control logic. These constructs make the specification of access control requirements more compact than decision trees, which can be considered the most natural way to specify access control logic. However, many publications report that performance of XACML policy decision point (PDP) engines is greatly affected by the structure of policy sets. In this paper we first explore the causes of potential inefficiencies of XACML policies, and then propose a procedure to re-structure policy sets vertically by modifying the distribution of access control logic among different configurations of structural elements, in order to remove much of this inefficiency. This is in contrast to horizontal re-ordering of constant structural elements. Our procedure can be applied regardless of the complexity and structure of the original policy set. We also compare the performance of policy sets that take advantage of the expressive power of XACML targets to decision trees.
  • Keywords
    XML; authorisation; formal specification; XACML policy decision point engines; access control logic distribution; access control requirement specification; constant structural elements; declarative access control policy language; extensible access control mark-up language; language constructs; policy sets; structural elements; Access control; Algorithm design and analysis; Computer science; Decision trees; Educational institutions; Process control; Redundancy; XACML; access control; policy restructuring;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2014 Ninth International Conference on
  • Conference_Location
    Fribourg
  • Type

    conf

  • DOI
    10.1109/ARES.2014.38
  • Filename
    6980287