Access control policy management based on extended-XACML
|更新时间:2024-10-14
|
Access control policy management based on extended-XACML
Issue 1, Pages: 103-110(2007)
作者机构:
1. 中国科学院软件研究所信息安全国家重点实验室
2. 中国科学院软件研究所信息安全国家重点实验室,北京,100080
作者简介:
基金信息:
DOI:
CLC:TP312.2
Published:2007
稿件说明:
移动端阅览
LI Xiao-feng, FENG Deng-guo, XU Zheng. Access control policy management based on extended-XACML[J]. 2007, (1): 103-110.
DOI:
LI Xiao-feng, FENG Deng-guo, XU Zheng. Access control policy management based on extended-XACML[J]. 2007, (1): 103-110.DOI:
Access control policy management based on extended-XACML
摘要
在XACML(extensible access control markup language)和其管理性策略草案的基础上
针对目前XACML访问控制框架的特点
提出将XACML策略管理权限判定归结为利用委托策略对一个委托判定请求的判定
使用XML(extensible markup language)模式定义了此委托判定请求语法
描述了将策略管理请求规约为一个委托判定请求的过程
以及根据委托策略进行委托判定请求的判定过程
通过这种方法可以利用委托策略
对策略管理请求是否有效进行判断
从而实现基于扩展XACML的策略管理。
Abstract
Based on XACML core specification and XACML administrative policy draft
a decision of XACML policy management permission was reduced to a decision of delegation decision request.The delegation decision request schema was defined.It was described that the process of reducing a policy administration request to a delegation decision request and the decision process of delegation decision request.This method can be used to check if a policy administra-tion request is valid and thereby to implement access control policy management based on extended-XACML.