An XACML Policy Generating Method Based on Policy View
Bo Lang, Nan Zhao, Kun Ge, Kai Chen
Abstract
Bo Lang, Nan Zhao, Kun Ge, Kai Chen
Abstract
Attribute Based Access Control (ABAC) is a promising access control model for pervasive computing. XACML is recognized as an effective ABAC policy description method that can exactly describe the semantics of a policy. However, the description of a XACML policy is complex and it is difficult for users to compose such a policy, which seriously embarrasses the application of XACML. Aiming at this problem, this paper presents an XACML policy generating method basing on a user-oriented ABAC policy view. On the basis of analyzing the XACML policy description language, the paper first establishes a policy description template composed of primary policy description elements of XACML, and then proposes an ABAC concept model called Access Control Cube (ACCube) and submits a comprehensible user-oriented policy view basing on the ACCube. The policy view and the XACML policy template provide an easy and effective way for users to define XACML policies. Users can describe their ABAC policies by creating the policy views, which can then be transformed into XACML policies. The transforming algorithm is given in the paper. According to the foregoing method, we develop a XACML policy generating tool named XACML Policy Builder. An example of using XACML Policy Builder for building XACML policy is also given.
OpenAlex reports 15 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Attribute Based Access Control (ABAC) is a promising access control model for pervasive computing. XACML is recognized as an effective ABAC policy description method that can exactly describe the semantics of a policy. However, the description of a XACML policy is complex and it is difficult for users to compose such a policy, which seriously embarrasses the application of XACML. Aiming at this problem, this paper presents an XACML policy generating method basing on a user-oriented ABAC policy view. On the basis of analyzing the XACML policy description language, the paper first establishes a policy description template composed of primary policy description elements of XACML, and then proposes an ABAC concept model called Access Control Cube (ACCube) and submits a comprehensible user-oriented policy view basing on the ACCube. The policy view and the XACML policy template provide an easy and effective way for users to define XACML policies. Users can describe their ABAC policies by creating the policy views, which can then be transformed into XACML policies. The transforming algorithm is given in the paper. According to the foregoing method, we develop a XACML policy generating tool named XACML Policy Builder. An example of using XACML Policy Builder for building XACML policy is also given.
Key concepts: XACML, Computer science, Access control, Markup language, Database, Computer security, World Wide Web, XML