A Non-Technical XACML Target Editor for Dynamic Access Control Systems

被引:0
|
作者
Stepien, Bernard [1 ]
Felty, Amy [1 ]
Matwin, Stan [2 ]
机构
[1] Univ Ottawa, Sch Elect Engn & Comp Sci, Ottawa, ON, Canada
[2] Dalhousie Univ, Polish Acad Sci, Fac Comp Sci, Canada Inst Comp Sci, Halifax, NS, Canada
关键词
component; Access control; XACML; policy administration point; ABAC; RBAC;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
XACML is a powerful and flexible access control (AC) policy language. It is an OASIS standard that is now widely used in a variety of applications, particularly those that require interoperability between AC systems. The language definition includes a precise grammar, syntax, and semantics, and it is both expressive and verbose. This combination of expressive power and verbosity can lead to difficulty in understanding the language's syntax and semantics for both technical and nontechnical users alike. As a result, reducing the difficulty of editing XACML policies has become an intense area of research. In our own work in this area, we previously showed how to render complex XACML conditions using a non-technical display notation and showed that it is easy to use this notation with interactive plain text editors that do not require any technical coding. Although XACML conditions are expressive and flexible, XACML targets are actually the most commonly used XACML language construct. They have an additional level of complexity, especially in version 3.0, due to the fact that the form and kinds of XACML constructs allowed in targets is much more limited. This paper extends our previous work, showing how the same powerful and flexible interactive editing principles can be applied to targets in order to allow users to use natural logic rather than implementation logic. We extend these principles and fully integrate them into our editing tool, easyXACML. This tool is usable by users with no technical knowledge of XACML, thus making XACML totally transparent to the user, while still retaining all of its functionalities and semantics. Our tool thus allows users to focus on policy logic rather than on details of syntax. As a result, the risk of errors in policies is greatly reduced.
引用
收藏
页码:150 / 157
页数:8
相关论文
共 50 条
  • [41] Too little or too much? Exploring the effectiveness of different policies in air pollution control from technical and non-technical pathways
    Ma, Xiaowei
    Sun, Qingyu
    Wang, Mei
    Li, Chuandong
    JOURNAL OF ENVIRONMENTAL MANAGEMENT, 2024, 369
  • [42] Identification of Non-Technical Electricity Losses in Power Distribution Systems by Applying Techniques of Information Analysis and Visualization
    Porras, J. A.
    Rivera, H. O.
    Giraldo, F. D.
    Correa, B. S. A.
    IEEE LATIN AMERICA TRANSACTIONS, 2015, 13 (03) : 659 - 664
  • [43] Electricity Non-Technical Loss Detection: Enhanced Cost-Driven Approach Utilizing Synthetic Control
    Alharbi, Meshal
    Alghumayjan, Saud
    Alsaleh, Mansour
    Shah, Devavrat
    Alabdulkareem, Ahmad
    2021 IEEE POWER & ENERGY SOCIETY INNOVATIVE SMART GRID TECHNOLOGIES CONFERENCE (ISGT), 2021,
  • [44] Follow-up and preventive control of non-technical losses of energy in CA Electricidad de Valencia
    Iglesias, Jose Manuel Rodriguez
    2006 IEEE/PES TRANSMISSION & DISTRIBUTION CONFERENCE & EXPOSITION: LATIN AMERICA, VOLS 1-3, 2006, : 667 - 671
  • [45] Access Control Enforcement Architectures for Dynamic Manufacturing Systems
    Leander, Bjorn
    Causevic, Aida
    Lindstrom, Tomas
    Hansson, Hans
    2023 IEEE 20TH INTERNATIONAL CONFERENCE ON SOFTWARE ARCHITECTURE, ICSA, 2023, : 82 - 92
  • [46] Strategic plan for the control and reduction of non-technical losses applied in CA energia electrica de valencia
    Gonzalez, Gustavo
    Figueroa, Luis
    2006 IEEE/PES TRANSMISSION & DISTRIBUTION CONFERENCE & EXPOSITION: LATIN AMERICA, VOLS 1-3, 2006, : 1379 - 1384
  • [47] Towards Dynamic Access Control for Healthcare Information Systems
    Rostad, Lillian
    Nytro, Oystein
    EHEALTH BEYOND THE HORIZON - GET IT THERE, 2008, 136 : 703 - 708
  • [48] Dynamic Authentication with Sensory Information for the Access Control Systems
    Shu, Yuanchao
    Gu, Yu
    Chen, Jiming
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2014, 25 (02) : 427 - 436
  • [49] Distributed, dynamic and trustworthy access control for telehealth systems
    Zerga, Hideyat
    Amraoui, Asma
    Benmammar, Badr
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2022, 34 (28):
  • [50] Comparing BeadChip and WGS Genotyping: Non-Technical Failed Calling Is Attributable to Additional Variation within the Probe Target Sequence
    Gershoni, Moran
    Shirak, Andrey
    Raz, Rotem
    Seroussi, Eyal
    GENES, 2022, 13 (03)