A Holistic Approach to Security Policies -- Policy Distribution with XACML over COPS

  • Authors:
  • Jan Peters;Roland Rieke;Taufiq Rochaeli;Björn Steinemann;Ruben Wolf

  • Affiliations:
  • Fraunhofer Institute for Computer Graphics Research IGD, Germany;Fraunhofer Institute for Secure Information Technology SIT, Germany;Technical University of Darmstadt, Department of Computer Science, IT-Security group, Germany;Fraunhofer Institute for Secure Information Technology SIT, Germany;Fraunhofer Institute for Secure Information Technology SIT, Germany

  • Venue:
  • Electronic Notes in Theoretical Computer Science (ENTCS)
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

The potentials of modern information technology can only be exploited, if the underlying infrastructure and the applied applications sufficiently take into account all aspects of IT security. This paper presents the platform architecture of the SicAri project, which aims to build a security platform for ubiquitous Internet usage, and gives an overview of the implicitly and explicitly used security mechanisms to enable access control for service oriented applications in distributed environments. The paper will introduce the security policy integration concept with a special focus on distribution of security policies within the service infrastructure for transparent policy enforcement. We describe in details our extensions of the COPS protocol to transport XACML payload for security policy distribution and policy decision requests/responses.