XML-based distributed access control system

被引:0
|
作者
López, J [1 ]
Maña, A [1 ]
Yagüe, MI [1 ]
机构
[1] Univ Malaga, Dept Comp Sci, Malaga, Spain
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The use of attribute certificates and the concept of mobile policies have been proposed to overcome some of the limitations of the role based access control (RBAC) paradigm and to implement security requirements such as the "originator controlled" (ORCON) policy. Mobile policies are attached to the data that they control and enforced by their execution in trusted servers. In this paper we extend this idea to allow the execution of the policies in untrusted systems. Our extension allows policies to be bound to the data but not attached to. Through this modification security administrators are able to change policies dynamically and transparently. Additionally, we introduce X-ACS, an XML-based language designed to express policies in a simple and unambiguous way overcoming the limitations of other approaches. Important features of X-ACS are that it can be used by processors with limited capabilities such as smart cards while allowing the automated validation of policies.
引用
收藏
页码:203 / 213
页数:11
相关论文
共 50 条
  • [1] XML-based declarative access control
    Steele, R
    Gardner, W
    Dillon, TS
    Erradi, A
    SOFSEM 2005:THEORY AND PRACTICE OF COMPUTER SCIENCE, 2005, 3381 : 310 - 319
  • [2] A model of XML-based distributed measurement system
    Le, B
    Liu, Z
    Gu, TX
    PROCEEDINGS OF THE THIRD INTERNATIONAL SYMPOSIUM ON INSTRUMENTATION SCIENCE AND TECHNOLOGY, VOL 1, 2004, : 1351 - 1355
  • [3] An XML-based language for access control specifications in an RBAC environment
    Stoupa, KE
    Vakali, AI
    2003 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN AND CYBERNETICS, VOLS 1-5, CONFERENCE PROCEEDINGS, 2003, : 1717 - 1722
  • [4] The XML-Based Context-Constraint Access Control Policy
    Zhang, Zhikun
    Xiao, Jianguo
    Geng, Youping
    Li, Hanyi
    2009 INTERNATIONAL CONFERENCE ON NEW TRENDS IN INFORMATION AND SERVICE SCIENCE (NISS 2009), VOLS 1 AND 2, 2009, : 1009 - +
  • [5] A comparison of modeling strategies in defining XML-based access control languages
    Ardagna, C
    di Vimercati, SD
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2004, 19 (03): : 141 - 149
  • [6] An XML-based distributed spatial data engine
    Tan, YM
    Chi, TH
    Tang, ZS
    WAVELET ANALYSIS AND ITS APPLICATIONS, AND ACTIVE MEDIA TECHNOLOGY, VOLS 1 AND 2, 2004, : 881 - 886
  • [7] A XML-based distributed workflow modeling tools
    Wang, G. Q.
    Wang, G.
    Lv, M.
    E-ENGINEERING & DIGITAL ENTERPRISE TECHNOLOGY, 2008, 10-12 : 230 - 234
  • [8] Design and implementation of XML-based configuration management system for distributed systems
    Choi, HM
    Choi, MJ
    Hong, JW
    NOMS 2004: IEEE/IFIP NETWORK OPERATIONS AND MANAGMENT SYMPOSIUM: MANAGING NEXT GENERATION CONVERGENCE NETWORKS AND SERVICES, 2004, : 831 - 844
  • [9] XML-based revocation and delegation in a distributed environment
    Stoupa, K
    Vakali, A
    Li, F
    Tsoukalas, I
    CURRENT TRENDS IN DATABASE TECHNOLOGY - EDBT 2004 WORKSHOPS, PROCEEDINGS, 2004, 3268 : 299 - 308
  • [10] An XML-Based protocol for distributed event services
    Smith, W
    Gunter, D
    Quesnel, D
    PDPTA'2001: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED PROCESSING TECHNIQUES AND APPLICATIONS, 2001, : 1668 - 1674