• DocumentCode
    2952815
  • Title

    Overriding of Access Control in XACML

  • Author

    Alqatawna, Ja Far ; Rissanen, Erik ; Sadighi, Babak

  • Author_Institution
    Swedish Inst. of Comput. Sci, Stockholm
  • fYear
    2007
  • fDate
    13-15 June 2007
  • Firstpage
    87
  • Lastpage
    95
  • Abstract
    Most access control mechanisms focus on how to define the rights of users in a precise way to prevent any violation of the access control policy of an organization. However, in many cases it is hard to predefine all access needs, or even to express them in machine readable form. One example of such a situation is an emergency case which may not be predictable and would be hard to express as a machine readable condition. Discretionary overriding of access control is one way for handling such hard to define and unanticipated situations where availability is critical. The override mechanism gives the subject of the access control policy the possibility to override a denied decision, and if the subject should confirm the override, the access will be logged for special auditing. XACML, the extensible access control markup language, provides a standardized access control policy language for expressing access control policies. This paper introduces a discretionary overriding mechanism in XACML. We do so by means of XACML obligations and also define a general obligation combining mechanism.
  • Keywords
    XML; authorisation; XACML; access control; discretionary overriding; extensible access control markup language; machine readable condition; Access control; Computer science; Computer security; Data privacy; Hospitals; Markup languages; Permission; Physics computing; Silicon carbide;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Policies for Distributed Systems and Networks, 2007. POLICY '07. Eighth IEEE International Workshop on
  • Conference_Location
    Bologna
  • Print_ISBN
    0-7695-2767-1
  • Type

    conf

  • DOI
    10.1109/POLICY.2007.31
  • Filename
    4262576