Title :
A language driven approach to multi-system access control
Author :
Davy, Steven ; Barron, Jonathan ; Lei Shi ; Butler, B. ; Jennings, Brendan ; Griffin, K. ; Collins, Ken
Author_Institution :
Telecommun. Software & Syst. Group, Waterford Inst. of Technol., Waterford, Ireland
Abstract :
Resource access control policies for an organization are often derived from best practice standards or from high level business policies. To ensure that access control is enforced effectively, these business policies need to be translated into deployable system configurations or lower level policies for multiple diverse systems. These target policy representations require experts to coordinate and collaborate so that business policies are fully supported. It is difficult and cumbersome to effectively ensure that all access control policies are enforced with the desired effect and in a consistent way, particularly given that there may be many people editing policies and that business policies can change over time. We present a language driven approach that abstracts access control policies into a clear and structured set of rules defined using terms familiar to a non-systems expert, which may then be realized into multiple levels of abstraction. Our proof of concept system uses Language-Driven Development (LDD) techniques to transform high level business policies into device specific policies that can be enforced by multiple access control system types. Our scenario examines the application of access control to instant messaging communications and network server access, two systems with different access control configuration languages.
Keywords :
authorisation; electronic messaging; LDD techniques; access control configuration languages; access control policies; business policies; device specific policies; instant messaging communications; language driven approach; language-driven development; multiple access control system; multisystem access control; network server access; target policy representations; Abstracts; Access control; Knowledge based systems; Ontologies; Organizations;
Conference_Titel :
Integrated Network Management (IM 2013), 2013 IFIP/IEEE International Symposium on
Conference_Location :
Ghent
Print_ISBN :
978-1-4673-5229-1