DocumentCode
182011
Title
Challenges of Composing XACML Policies
Author
Stepien, Bernard ; Felty, Amy ; Matwin, S.
Author_Institution
Sch. of Inf. Technol. & Eng., Univ. of Ottawa, Ottawa, ON, Canada
fYear
2014
fDate
8-12 Sept. 2014
Firstpage
234
Lastpage
241
Abstract
XACML (extensible Access Control Mark-up Language) is a declarative access control policy language that has unique language constructs for factoring out access control logic. These constructs make the specification of access control requirements more compact than decision trees, which can be considered the most natural way to specify access control logic. However, many publications report that performance of XACML policy decision point (PDP) engines is greatly affected by the structure of policy sets. In this paper we first explore the causes of potential inefficiencies of XACML policies, and then propose a procedure to re-structure policy sets vertically by modifying the distribution of access control logic among different configurations of structural elements, in order to remove much of this inefficiency. This is in contrast to horizontal re-ordering of constant structural elements. Our procedure can be applied regardless of the complexity and structure of the original policy set. We also compare the performance of policy sets that take advantage of the expressive power of XACML targets to decision trees.
Keywords
XML; authorisation; formal specification; XACML policy decision point engines; access control logic distribution; access control requirement specification; constant structural elements; declarative access control policy language; extensible access control mark-up language; language constructs; policy sets; structural elements; Access control; Algorithm design and analysis; Computer science; Decision trees; Educational institutions; Process control; Redundancy; XACML; access control; policy restructuring;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security (ARES), 2014 Ninth International Conference on
Conference_Location
Fribourg
Type
conf
DOI
10.1109/ARES.2014.38
Filename
6980287
Link To Document