【24h】

Offline Expansion of XACML Policies Based on P3P Metadata

机译:基于P3P元数据的XACML策略的脱机扩展

获取原文
获取原文并翻译 | 示例

摘要

In the last few years XML-based access control languages like XACML have been increasingly used for specifying complex policies regulating access to network resources. Today, growing interest in semantic-Web style metadata for describing resources and users is stimulating research on how to express access control policies based on advanced descriptions rather than on single attributes. In this paper, we discuss how standard XACML policies can handle ontology-based resource and subject descriptions based on the standard P3P base data schema. We show that XACML conditions can be transparently expanded according to ontology-based models representing semantics. Our expansion technique greatly reduces the need for online reasoning and decreases the system administrator's effort for producing consistent rules when users' descriptions comprise multiple credentials with redundant attributes.
机译:在过去的几年中,越来越多地使用基于XML的访问控制语言(如XACML)来指定复杂的策略,以控制对网络资源的访问。如今,对于用于描述资源和用户的语义Web样式元数据的兴趣日益浓厚,这刺激了有关如何基于高级描述而不是单个属性来表达访问控制策略的研究。在本文中,我们将讨论标准XACML策略如何基于标准P3P基础数据模式处理基于本体的资源和主题描述。我们展示了XACML条件可以根据表示语义的基于本体的模型透明地扩展。当用户的描述包含具有冗余属性的多个凭据时,我们的扩展技术极大地减少了在线推理的需求,并减少了系统管理员为生成一致规则而付出的努力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号