Security Policy Reconciliation in Distributed Computing Environments

  • Authors:
  • Affiliations:
  • Venue:
  • POLICY '04 Proceedings of the Fifth IEEE International Workshop on Policies for Distributed Systems and Networks
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

A major hurdle in sharing resources between organizationsis heterogeneity. Therefore, in order for two organizationsto collaborate their policies have to be resolved. Theprocess of resolving different policies is known as policyreconciliation, which in general is an intractable problem.This paper addresses policy reconciliation in the context ofsecurity. We present a formal framework and hierarchicalrepresentation for security policies. Our hierarchical representationexposes the structure of the policies and leads toan efficient reconciliation algorithm. We also demonstratethat agent preferences for security mechanisms can be readilyincorporated into our framework. We have implementedour reconciliation algorithm in a library called the PolicyReconciliation Engine or PRE. In order to test the implementationand measure the overhead of our reconciliationalgorithm, we have integrated PRE into a distributed high-throughputsystem called Condor.