DocumentCode :
2207247
Title :
Decentralized XACML Overlay Network
Author :
Alzahrani, Ali ; Janicke, Helge ; Abubaker, Sarshad
Author_Institution :
Software Technol. Res. Lab., De Montfort Univ., Leicester, UK
fYear :
2010
fDate :
June 29 2010-July 1 2010
Firstpage :
1032
Lastpage :
1037
Abstract :
We propose a novel approach for the collaborative enforcement of security policies in distributed systems that is based on the dynamic (re-) deployment of multiple PDPs. The policies enforced by the collaborating PDPs are analysed and decomposed from a system wide policy as present in current centralized approaches. The security policy is decomposed into sub-policies based on an object domain approach so the decisions are local to the object´s domain. The classes of policies investigated are dynamic history-based access control policies, ie. the PDPs decision is dependent on the history of interaction between users and system resources. This type of policy can capture static and dynamic separation of duty policies, as are commonly found in commercial organisations. The distribution model of the PDP allows for the coordination and synchronisation of PDPs on the basis of events, where a decision is based on a previous history originating from other PDPs. The key contribution of this paper is the analysis of temporal dependencies between policies and an efficient PDP distribution strategy for object-based distributed systems as well as presenting a designed library that create and synchronize a network of PDP´s in a peer to peer fashion.
Keywords :
XML; authorisation; distributed processing; groupware; collaborative policy enforcement; decentralized XACML overlay network; dynamic history-based access control; multiple PDP; object domain approach; object-based distributed system; security policy; Access control; Decision making; History; Libraries; Prototypes; Synchronization; PDPs coordination; collaborative policy enforcement; decentralised policy enforcement;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer and Information Technology (CIT), 2010 IEEE 10th International Conference on
Conference_Location :
Bradford
Print_ISBN :
978-1-4244-7547-6
Type :
conf
DOI :
10.1109/CIT.2010.189
Filename :
5578621
Link To Document :
بازگشت