کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
453520 694950 2012 8 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Decision-cache based XACML authorisation and anonymisation for XML documents
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Decision-cache based XACML authorisation and anonymisation for XML documents
چکیده انگلیسی

This paper describes a decision cache for the eXtensible Access Control Markup Language (XACML) that supports fine-grained authorisation and anonymisation of XML based messages and documents down to XML attribute and element level. The decision cache is implemented as an XACML obligation service, where a specification of the XML elements to be authorised and anonymised is sent to the Policy Enforcement Point (PEP) during initial authorisation. Further authorisation of individual XML elements according to the authorisation specification is then performed on all matching XML resources, and decisions are stored in the decision cache. This makes it possible to cache fine-grained XACML authorisation and anonymisation decisions, which reduces the authorisation load on the Policy Decision Point (PDP). The theoretical solution is related to a practical case study consisting of a privacy-enhanced intrusion detection system that needs to perform anonymisation of Intrusion Detection Message Exchange Format (IDMEF) XML messages before they are sent to a security operations centre that operates in privacy-preserving mode. The solution increases the scalability of XACML based authorisation significantly, and may be instrumental in implementing federated authorisation and anonymisation based on XACML in several areas, including intrusion detection systems, web services, content management systems and GRID based authentication and authorisation.


► This paper describes an XACML decision cache.
► It supports fine-grained anonymisation of XML elements and attributes.
► The decision cache improves XACML performance significantly.
► The solution demonstrates anonymisation of IDMEF XML reports for intrusion detection systems.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computer Standards & Interfaces - Volume 34, Issue 6, November 2012, Pages 527–534
نویسندگان
, ,