Deductive policies with XACML

  • Authors:
  • Mario Lischka;Yukiko Endo;Manuel Sánchez Cuenca

  • Affiliations:
  • NEC Europe Ltd., Heidelberg, Germany;NEC Europe Ltd., Heidelberg, Germany;University of Murcia, Murcia, Spain

  • Venue:
  • Proceedings of the 2009 ACM workshop on Secure web services
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

SaaS technology might comprise of a bundle of different services provided by different entities. Thus monolithic access policies are not feasible as each of the service partners and the companies using the service would have to provide their internal and potentially confidential rules on which they base their policies. In addition internal information such as concrete position of the user or affiliation to a specific project might be utilized in the policies and should not be provided to any external entity. Deduction of decisions has been investigated for more than a decade, but no widely spread standard has been defined, so far. OASIS XACML is being used in many applications and services nowadays. Additionally, tools for modeling the policies are available and many engineers share common understanding of this approach. In this paper we present an extension of the XACML language to support deduction of decisions, together with a distributed definition of the policies and at the same time avoiding problems known from current solutions on deductive policy languages.