XACML policy integration algorithms: not to be confused with XACML policy combination algorithms!

  • Authors:
  • P. Mazzoleni;E. Bertino;B. Crispo;S. Sivasubramanian

  • Affiliations:
  • University of Milan, Italy;Purdue University, USA;Vrije Universiteit, Amsterdam and University of Trento, Italy;Vrije Universiteit, Amsterdam

  • Venue:
  • Proceedings of the eleventh ACM symposium on Access control models and technologies
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

XACML is the OASIS standard language for the specification of authorization and entitlement policies. However, while XACML well addresses security requirements of a single enterprise (even if large and composed by multiple departments), it does not address the requirements of virtual enterprises built through collaboration of several autonomous subjects sharing their resources. In this paper we highlight such limitations and we propose an XACML extension, the policy integration algorithm, to address them. In the paper we also discuss in which respect the process of comparing two XACML policies differs from the process used to compare other business rules.