DocumentCode
627554
Title
A language driven approach to multi-system access control
Author
Davy, Steven ; Barron, Jonathan ; Lei Shi ; Butler, B. ; Jennings, Brendan ; Griffin, K. ; Collins, Ken
Author_Institution
Telecommun. Software & Syst. Group, Waterford Inst. of Technol., Waterford, Ireland
fYear
2013
fDate
27-31 May 2013
Firstpage
1004
Lastpage
1008
Abstract
Resource access control policies for an organization are often derived from best practice standards or from high level business policies. To ensure that access control is enforced effectively, these business policies need to be translated into deployable system configurations or lower level policies for multiple diverse systems. These target policy representations require experts to coordinate and collaborate so that business policies are fully supported. It is difficult and cumbersome to effectively ensure that all access control policies are enforced with the desired effect and in a consistent way, particularly given that there may be many people editing policies and that business policies can change over time. We present a language driven approach that abstracts access control policies into a clear and structured set of rules defined using terms familiar to a non-systems expert, which may then be realized into multiple levels of abstraction. Our proof of concept system uses Language-Driven Development (LDD) techniques to transform high level business policies into device specific policies that can be enforced by multiple access control system types. Our scenario examines the application of access control to instant messaging communications and network server access, two systems with different access control configuration languages.
Keywords
authorisation; electronic messaging; LDD techniques; access control configuration languages; access control policies; business policies; device specific policies; instant messaging communications; language driven approach; language-driven development; multiple access control system; multisystem access control; network server access; target policy representations; Abstracts; Access control; Knowledge based systems; Ontologies; Organizations;
fLanguage
English
Publisher
ieee
Conference_Titel
Integrated Network Management (IM 2013), 2013 IFIP/IEEE International Symposium on
Conference_Location
Ghent
Print_ISBN
978-1-4673-5229-1
Type
conf
Filename
6573122
Link To Document