DocumentCode
2952815
Title
Overriding of Access Control in XACML
Author
Alqatawna, Ja Far ; Rissanen, Erik ; Sadighi, Babak
Author_Institution
Swedish Inst. of Comput. Sci, Stockholm
fYear
2007
fDate
13-15 June 2007
Firstpage
87
Lastpage
95
Abstract
Most access control mechanisms focus on how to define the rights of users in a precise way to prevent any violation of the access control policy of an organization. However, in many cases it is hard to predefine all access needs, or even to express them in machine readable form. One example of such a situation is an emergency case which may not be predictable and would be hard to express as a machine readable condition. Discretionary overriding of access control is one way for handling such hard to define and unanticipated situations where availability is critical. The override mechanism gives the subject of the access control policy the possibility to override a denied decision, and if the subject should confirm the override, the access will be logged for special auditing. XACML, the extensible access control markup language, provides a standardized access control policy language for expressing access control policies. This paper introduces a discretionary overriding mechanism in XACML. We do so by means of XACML obligations and also define a general obligation combining mechanism.
Keywords
XML; authorisation; XACML; access control; discretionary overriding; extensible access control markup language; machine readable condition; Access control; Computer science; Computer security; Data privacy; Hospitals; Markup languages; Permission; Physics computing; Silicon carbide;
fLanguage
English
Publisher
ieee
Conference_Titel
Policies for Distributed Systems and Networks, 2007. POLICY '07. Eighth IEEE International Workshop on
Conference_Location
Bologna
Print_ISBN
0-7695-2767-1
Type
conf
DOI
10.1109/POLICY.2007.31
Filename
4262576
Link To Document