LI Xiao-feng, FENG Deng-guo, XU Zheng. Access control policy management based on extended-XACML[J]. 2007, (1): 103-110.DOI:
基于扩展XACML的策略管理
摘要
在XACML(extensible access control markup language)和其管理性策略草案的基础上
针对目前XACML访问控制框架的特点
提出将XACML策略管理权限判定归结为利用委托策略对一个委托判定请求的判定
使用XML(extensible markup language)模式定义了此委托判定请求语法
描述了将策略管理请求规约为一个委托判定请求的过程
以及根据委托策略进行委托判定请求的判定过程
通过这种方法可以利用委托策略
对策略管理请求是否有效进行判断
从而实现基于扩展XACML的策略管理。
Abstract
Based on XACML core specification and XACML administrative policy draft
a decision of XACML policy management permission was reduced to a decision of delegation decision request.The delegation decision request schema was defined.It was described that the process of reducing a policy administration request to a delegation decision request and the decision process of delegation decision request.This method can be used to check if a policy administra-tion request is valid and thereby to implement access control policy management based on extended-XACML.