A Non-Technical XACML Target Editor for Dynamic Access Control Systems

被引:0
|
作者
Stepien, Bernard [1 ]
Felty, Amy [1 ]
Matwin, Stan [2 ]
机构
[1] Univ Ottawa, Sch Elect Engn & Comp Sci, Ottawa, ON, Canada
[2] Dalhousie Univ, Polish Acad Sci, Fac Comp Sci, Canada Inst Comp Sci, Halifax, NS, Canada
关键词
component; Access control; XACML; policy administration point; ABAC; RBAC;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
XACML is a powerful and flexible access control (AC) policy language. It is an OASIS standard that is now widely used in a variety of applications, particularly those that require interoperability between AC systems. The language definition includes a precise grammar, syntax, and semantics, and it is both expressive and verbose. This combination of expressive power and verbosity can lead to difficulty in understanding the language's syntax and semantics for both technical and nontechnical users alike. As a result, reducing the difficulty of editing XACML policies has become an intense area of research. In our own work in this area, we previously showed how to render complex XACML conditions using a non-technical display notation and showed that it is easy to use this notation with interactive plain text editors that do not require any technical coding. Although XACML conditions are expressive and flexible, XACML targets are actually the most commonly used XACML language construct. They have an additional level of complexity, especially in version 3.0, due to the fact that the form and kinds of XACML constructs allowed in targets is much more limited. This paper extends our previous work, showing how the same powerful and flexible interactive editing principles can be applied to targets in order to allow users to use natural logic rather than implementation logic. We extend these principles and fully integrate them into our editing tool, easyXACML. This tool is usable by users with no technical knowledge of XACML, thus making XACML totally transparent to the user, while still retaining all of its functionalities and semantics. Our tool thus allows users to focus on policy logic rather than on details of syntax. As a result, the risk of errors in policies is greatly reduced.
引用
收藏
页码:150 / 157
页数:8
相关论文
共 50 条
  • [31] Utility and assessment of non-technical skills for rapid response systems and medical emergency teams
    Chalwin, R. P.
    Flabouris, A.
    INTERNAL MEDICINE JOURNAL, 2013, 43 (09) : 962 - 969
  • [32] Communication Networks and Non-Technical Energy Loss Control System for Smart Grid Networks
    Rengaraju, Perumalraja
    Pandian, Shunmugham R.
    Lung, Chung-Horng
    2014 IEEE INNOVATIVE SMART GRID TECHNOLOGIES - ASIA (ISGT ASIA), 2014, : 418 - 423
  • [33] Defining the capable engineer: Non-technical skills that support safe decisions in uncertain, dynamic situations
    Hayes, Jan
    Maslen, Sarah
    Holdsworth, Sarah
    Sandri, Orana
    SAFETY SCIENCE, 2021, 141
  • [34] XACMET: XACML Testing & Modeling An automated model-based testing solution for access control systems
    Daoudagh, Said
    Lonetti, Francesca
    Marchetti, Eda
    SOFTWARE QUALITY JOURNAL, 2020, 28 (01) : 249 - 282
  • [35] XACMET: XACML Testing & ModelingAn automated model-based testing solution for access control systems
    Said Daoudagh
    Francesca Lonetti
    Eda Marchetti
    Software Quality Journal, 2020, 28 : 249 - 282
  • [36] Using 0.6 kV/1 kV Low Voltage in Distribution Systems for the Reduction of the Technical and Non-Technical Energy Losses
    Hasan, Hamza
    Mozumdar, Mohmmad
    Al-Jufout, Saleh
    2020 11TH INTERNATIONAL RENEWABLE ENERGY CONGRESS (IREC), 2020,
  • [37] Training and assessing technical and non-technical skills for uretersocopy within a simulation-based curriculum - a randomised control trial
    Brunckhorst, O.
    Shahid, S.
    Aydin, A.
    McIlhenny, C.
    Khan, S.
    Syed, J. R.
    Sahai, A.
    Brewin, J.
    Bello, F.
    Kneebone, R.
    Khan, M. S.
    Dasgupta, P.
    Ahmed, K.
    BRITISH JOURNAL OF SURGERY, 2015, 102 : 39 - 39
  • [38] An exploratory study of non-technical critical success factors of the implementation of enterprise information systems in China
    Min, QF
    Ji, SB
    PROCEEDINGS OF 2002 INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE & ENGINEERING, VOLS I AND II, 2002, : 146 - 150
  • [39] A Framework for Human-Agent Social Systems: The Role of Non-technical Factors in Operation Success
    Lohani, Monika
    Stokes, Charlene
    Dashan, Natalia
    McCoy, Marissa
    Bailey, Christopher A.
    Rivers, Susan E.
    ADVANCES IN HUMAN FACTORS IN ROBOTS AND UNMANNED SYSTEMS, 2017, 499 : 137 - 148
  • [40] Measure of the Impact of a STEM-Student-led Course on Privacy Enhancing Technologies for a non-Technical Target Population
    Wolf, Gunnar
    Miranda, Alejandro
    SIGCSE 2020: PROCEEDINGS OF THE 51ST ACM TECHNICAL SYMPOSIUM ON COMPUTER SCIENCE EDUCATION, 2020, : 1339 - 1339