首页> 外文会议>Communications and Multimedia Security; Lecture Notes in Computer Science; 4237 >Adding Support to XACML for Dynamic Delegation of Authority in Multiple Domains
【24h】

Adding Support to XACML for Dynamic Delegation of Authority in Multiple Domains

机译:为XACML添加支持以实现多个域中的动态授权

获取原文
获取原文并翻译 | 示例

摘要

In this paper we describe how we have added support for dynamic delegation of authority that is enacted via the issuing of credentials from one user to another, to the XACML model for authorisation decision making. Initially we present the problems and requirements that such a model demands, considering that multiple domains will typically be involved. We then describe our architected solution based on the XACML conceptual and data flow models. We also present at a conceptual level the policy elements that are necessary to support this model of dynamic delegation of authority. Given that these policy elements are significantly different to those of the existing XACML policy, we propose a new conceptual entity called the Credential Validation Service (CVS), to work alongside the XACML PDP in the authorisation decision making. Finally we present an overview of our first specification of such a policy and its implementation in the corresponding CVS.
机译:在本文中,我们描述了如何为通过授权从一个用户到另一个用户的凭据颁发而实现的动态授权委托添加到XACML模型以进行授权决策。最初,考虑到通常涉及多个领域,我们提出了该模型所要求的问题和要求。然后,我们基于XACML概念模型和数据流模型描述我们的体系结构解决方案。我们还在概念上提出了支持这种动态授权模式的必要政策要素。鉴于这些策略元素与现有XACML策略的元素明显不同,我们提出了一个新的概念实体,称为凭据验证服务(CVS),可以与XACML PDP一起进行授权决策。最后,我们概述了这种策略的第一个规范及其在相应CVS中的实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号