【24h】

A Heterogeneous Network Access Service Based on PERMIS and SAML

机译:基于PERMIS和SAML的异构网络访问服务

获取原文
获取原文并翻译 | 示例

摘要

The expansion of inter-organizational scenarios based on different authorization schemes involves the development of integration solutions allowing different authorization domains to share, in some way, protected resources. This paper analyzes different emerging technologies. On the one hand, we have two XML-based standards, the SAML standard, which is being widely accepted as a language to express and exchange authorization data, and the XACML standard, which constitutes a promising framework for access control policies. On the other hand, PERMIS is a trust management system for X.509 attribute certificates and includes a powerful authorization decision engine governed by the PERMIS XML policy. This paper presents a sample scenario where domains using these technologies can be integrated allowing, for example, the use of attribute certificates in a SAML environment and the utilization of the PERMIS authorization engine to decide about the disclosure or concealment of attributes. In order to design this scenario we have based our work on a Credential Conversion Service (CCS) which is able to convert ACs into SAML attributes, and a User Attribute Manager (UAM) which controls the disclosure of credentials. These modules are governed by policies defining the conversion process (the Conversion Policy) and the disclosure of attributes (the Disclosure Policy).
机译:基于不同授权方案的组织间场景的扩展涉及集成解决方案的开发,该解决方案允许不同的授权域以某种方式共享受保护的资源。本文分析了不同的新兴技术。一方面,我们有两个基于XML的标准:SAML标准和XACML标准,SAML标准已被广泛接受,该语言用于表达和交换授权数据,XACML标准构成了有希望的访问控制策略框架。另一方面,PERMIS是用于X.509属性证书的信任管理系统,并且包括一个受PERMIS XML策略控制的功能强大的授权决策引擎。本文提出了一个示例场景,其中可以集成使用这些技术的域,例如,允许在SAML环境中使用属性证书,以及使用PERMIS授权引擎来决定属性的公开或隐藏。为了设计此方案,我们的工作基于能够将AC转换为SAML属性的凭据转换服务(CCS)和控制凭据公开的用户属性管理器(UAM)。这些模块由定义转换过程的策略(转换策略)和属性公开(披露策略)控制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号