Meta-Policies for Distributed Role-Based Access Control Systems

  • Authors:
  • A. Belokosztolszki;K. Moody

  • Affiliations:
  • -;-

  • Venue:
  • POLICY '02 Proceedings of the 3rd International Workshop on Policies for Distributed Systems and Networks (POLICY'02)
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper meta-policies for access control policiesare presented. There has been a lot of research into the variousways of specifying policy for a single domain. Suchdomains are autonomous and can be managed by the usersor by a specific system administrator. It is often helpful tohave a more general policy description in order to restrictthe ways in which policy can be modified. Meta-policies fillthis particular role. With their help changes to policy canbe made subject to predefined constraints. Meta-policiesare long lived and so can provide users with stable informationabout the policy of the system. In addition theycan provide bodies external to a domain with relevant butrestricted information about its policies, so forming a basisfor co-operation between domains. For example, a domain'smeta-policy can function as a policy interface, thusestablishing a basis for agreement on the structure of theobjects accessed. In this way it is possible to build servicelevel agreements between domains automatically.