首页> 外文OA文献 >Modelling and Analysing Access Control Policies in XACML 3.0
【2h】

Modelling and Analysing Access Control Policies in XACML 3.0

机译:在XaCmL 3.0中建模和分析访问控制策略

摘要

XACML (eXtensible Access Control Markup Language) is a prominent access control language that is widely adopted both in industry and academia. XACML is an international standard in the field of information security. The problem with XACML is that its specification is described in natural language (c.f. GM03,Mos05,Ris13) and manual analysis of the overall effect and consequences of a large XACML policy set is a very daunting and time-consuming task.In this thesis we address the problem of understanding the semantics of access control policy language XACML, in particular XACML version 3.0. The main focus of this thesis is .There are two main contributions in this thesis. First, we study and formalise XACML 3.0, in particular the Policy Decision Point (PDP). The concrete syntax of XACML is based on the XML format, while its standard semantics is described normatively using natural language. The use of English text in standardisation leads to the risk of misinterpretation and ambiguity. In order to avoid this drawback, we define an abstract syntax of XACML 3.0 and a formal XACML semantics. Second, we propose a logic-based XACML analysis framework using Answer Set Programming (ASP). With ASP we model an XACML PDP that loads XACML policies and evaluates XACML requests against these policies. The expressivity of ASP and the existence of efficient implementations of the answer set semantics provide the means for declarative specification and verification of properties of XACML policies.Overall, we focus into two different area. The first part focuses on the access control language. More specifically our focus is on the understanding XACML 3.0. The second part focuses on how we use Logic Programming (LP) to model access control policies. We show that there is a relation between XACML and LP through their semantics. We close the thesis by presenting applications in analysing access control properties and a case study. These applications show that these two approaches (AC paradigm and LP paradigm) can be combined together.We close the thesis by presenting applications in analysing access control properties and a case study. We present access control security policies in a Smart Grid from Smart Meter perspective.
机译:XACML(可扩展访问控制标记语言)是一种杰出的访问控制语言,已在工业界和学术界广泛采用。 XACML是信息安全领域的国际标准。 XACML的问题在于它的规范是以自然语言描述的(参见GM03,Mos05,Ris13),而手动分析大型XACML策略集的整体效果和后果是一项非常艰巨且耗时的任务。解决了理解访问控制策略语言XACML(特别是XACML 3.0版)的语义问题。本文的重点是。本论文有两个主要贡献。首先,我们研究XACML 3.0,尤其是策略决策点(PDP),并将其形式化。 XACML的具体语法基于XML格式,而其标准语义则使用自然语言进行规范描述。在标准化中使用英语文本会导致误解和歧义的风险。为了避免此缺点,我们定义了XACML 3.0的抽象语法和正式的XACML语义。其次,我们提出了使用答案集编程(ASP)的基于逻辑的XACML分析框架。使用ASP,我们可以为XACML PDP建模,该PDP加载XACML策略并根据这些策略评估XACML请求。 ASP的可表达性和答案集语义的有效实现的存在为XACML策略的声明性规范和属性验证提供了手段。总体而言,我们将重点放在两个不同的领域。第一部分着重于访问控制语言。更具体地说,我们的重点是对XACML 3.0的理解。第二部分重点介绍如何使用逻辑编程(LP)建模访问控制策略。我们通过XACML和LP的语义显示了它们之间的关系。通过介绍在分析访问控制属性和案例研究中的应用,我们结束了本文。这些应用表明,这两种方法(AC范式和LP范式)可以组合在一起。本文通过介绍在分析访问控制属性和案例研究中的应用来结束本文。从智能电表的角度来看,我们在智能电网中提供了访问控制安全策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号