首页> 外文会议>International Conference on Signal Image Technology Internet Based Systems >A Performance Analysis of the XACML Decision Process and the Impact of Caching
【24h】

A Performance Analysis of the XACML Decision Process and the Impact of Caching

机译:XACML决策过程的性能分析和缓存的影响

获取原文

摘要

Whenever multiple service providers and high demanding service customers communicate with each other, the need of compliance to legal regulations and enterprise guidelines increases the expectations on technologies and systems used to ensure security and data privacy. Regarding the challenge of managing access rules and enforcing authorization to data and resources, OASIS' XACML standard provides a flexible and distributed approach. We provide an XACML-based authorization in the TRESOR Cloud Ecosystem "as a service" for SaaS providers and consumers. In this ecosystem the complexity and amount of access policies and rules raises scalability concerns. This paper explores the possibilities for caching and performance optimization in XACML, primarily focusing on XACML version 3 (XACMLv3) and its Policy Decision Point (PDP). We provide an overview of existing approaches to caching and performance optimization and conclude that most current approaches are concerned with the policy evaluation itself but not with finding applicable policies or loading and storing policies, rather attempting to increase performance through policy reconfiguration, translation, normalization or clustering. Furthermore, we explore the use of caching at specific points during the evaluation process, namely loading policies, finding policies and evaluation, for better performance along with other more general improvements.
机译:每当多个服务提供商和要求很高的服务客户相互通信时,对遵守法律法规和企业准则的需求都会增加对用于确保安全性和数据隐私的技术和系统的期望。关于管理访问规则和强制对数据和资源进行授权的挑战,OASIS的XACML标准提供了一种灵活的分布式方法。我们在TRESOR Cloud生态系统中“为服务”为SaaS提供者和消费者提供了基于XACML的授权。在这种生态系统中,访问策略和规则的复杂性和数量引发了可扩展性问题。本文探讨了XACML中的缓存和性能优化的可能性,主要关注XACML版本3(XACMLv3)及其策略决策点(PDP)。我们提供了有关缓存和性能优化的现有方法的概述,并得出结论,大多数当前方法与策略评估本身有关,而不与查找适用的策略或加载和存储策略有关,而是通过策略重新配置,转换,规范化或聚类。此外,我们探索了在评估过程中特定点使用缓存的方法,即加载策略,查找策略和评估,以实现更好的性能以及其他更一般的改进。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号