Offline expansion of XACML policies based on P3P metadata

10Citations
Citations of this article
13Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

In the last few years XML-based access control languages like XACML have been increasingly used for specifying complex policies regulating access to network resources. Today, growing interest in semantic-Web style metadata for describing resources and users is stimulating research on how to express access control policies based on advanced descriptions rather than on single attributes. In this paper, we discuss how standard XACML policies can handle ontology-based resource and subject descriptions based on the standard P3P base data schema. We show that XACML conditions can be transparently expanded according to ontology-based models representing semantics. Our expansion technique greatly reduces the need for online reasoning and decreases the system administrator's effort for producing consistent rules when users' descriptions comprise multiple credentials with redundant attributes. © Springer-Verlag Berlin Heidelberg 2005.

Cite

CITATION STYLE

APA

Ardagna, C., Damiani, E., De Capitani Di Vimercati, S., Fugazza, C., & Samarati, P. (2005). Offline expansion of XACML policies based on P3P metadata. In Lecture Notes in Computer Science (Vol. 3579, pp. 363–374). Springer Verlag. https://doi.org/10.1007/11531371_48

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free