2010 10th IEEE International Conference on Computer and Information Technology 2010
DOI: 10.1109/cit.2010.189
|View full text |Cite
|
Sign up to set email alerts
|

Decentralized XACML Overlay Network

Abstract: We propose a novel approach for the collaborative enforcement of security policies in distributed systems that is based on the dynamic (re-) deployment of multiple PDPs. The policies enforced by the collaborating PDPs are analysed and decomposed from a system wide policy as present in current centralized approaches. The security policy is decomposed into sub-policies based on an object domain approach so the decisions are local to the object's domain. The classes of policies investigated are dynamic history-ba… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
8
0

Year Published

2014
2014
2018
2018

Publication Types

Select...
2
2
1

Relationship

0
5

Authors

Journals

citations
Cited by 5 publications
(8 citation statements)
references
References 9 publications
0
8
0
Order By: Relevance
“…By submitting the form (1), a new ContractRequest (CR) object is created (2) and the web server sends the CR to a set of clerks via the mail server (3,4). One of the clerks will then review the attached CR (5) and start an analysis job on the internal data analysis server (6), thereby creating a new AnalysisResult (AR) object (7). Once the analysis is performed, the clerk retrieves the AR (8) and performs a manual review on her workstation (9).…”
Section: Running Examplementioning
confidence: 99%
See 3 more Smart Citations
“…By submitting the form (1), a new ContractRequest (CR) object is created (2) and the web server sends the CR to a set of clerks via the mail server (3,4). One of the clerks will then review the attached CR (5) and start an analysis job on the internal data analysis server (6), thereby creating a new AnalysisResult (AR) object (7). Once the analysis is performed, the clerk retrieves the AR (8) and performs a manual review on her workstation (9).…”
Section: Running Examplementioning
confidence: 99%
“…The authors Alzahrani et al [5,6] propose and implement an overlay network that allows for the dynamic and distributed deployment of multiple PDPs which are expected to collaboratively enforce history-based XACML policies such as dynamic separation of 168 6. Related Work duties [54].…”
Section: Distributed Policy Decisionsmentioning
confidence: 99%
See 2 more Smart Citations
“…According to the attributes contained within the targets in a policy or a rule, Kateb et al [29] decomposed the global policy into several subpolicies. Alzahrani et al [30] proposed an XACML distributed authorization model. In this model, the global policy in the centralized authorization model was decomposed into several subpolicies, which were deployed to corresponding PDPs.…”
Section: Introductionmentioning
confidence: 99%