DocumentCode :
2735465
Title :
An XACML Policy Generating Method Based on Policy View
Author :
Lang, Bo ; Zhao, Nan ; Ge, Kun ; Chen, Kai
Author_Institution :
State Key Lab. of Software Dev. Environ., Beihang Univ., Beijing
Volume :
1
fYear :
2008
fDate :
6-8 Oct. 2008
Firstpage :
295
Lastpage :
301
Abstract :
Attribute based access control (ABAC) is a promising access control model for pervasive computing. XACML is recognized as an effective ABAC policy description method that can exactly describe the semantics of a policy. However, the description of a XACML policy is complex and it is difficult for users to compose such a policy, which seriously embarrasses the application of XACML. Aiming at this problem, this paper presents an XACML policy generating method basing on a user-oriented ABAC policy view. On the basis of analyzing the XACML policy description language, the paper first establishes a policy description template composed of primary policy description elements of XACML, and then proposes an ABAC concept model called access control cube (ACCube) and submits a comprehensible user-oriented policy view basing on the ACCube. The policy view and the XACML policy template provide an easy and effective way for users to define XACML policies. Users can describe their ABAC policies by creating the policy views, which can then be transformed into XACML policies. The transforming algorithm is given in the paper. According to the foregoing method, we develop a XACML policy generating tool named XACML policy builder. An example of using XACML policy builder for building XACML policy is also given.
Keywords :
Web services; XML; authorisation; ubiquitous computing; ACCube; XACML policy description language; XACML policy generating method; access control cube; attribute based access control; pervasive computing; user-oriented ABAC policy; Access control; Buildings; Control systems; Internet; Pervasive computing; Security; Semiconductor optical amplifiers; Service oriented architecture; Usability; Web services; Attribute Based Access Control; Conceptual Policy Model; Policy Generation; User-oriented Policy View; XACML;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Pervasive Computing and Applications, 2008. ICPCA 2008. Third International Conference on
Conference_Location :
Alexandria
Print_ISBN :
978-1-4244-2020-9
Electronic_ISBN :
978-1-4244-2021-6
Type :
conf
DOI :
10.1109/ICPCA.2008.4783596
Filename :
4783596
Link To Document :
بازگشت