• Home
  • Search
  • A non-technical XACML target editor for dynamic access control systems
  • Cite Icon11
  • https://doi.org/10.1109/cts.2014.6867558Copy DOI Icon

A non-technical XACML target editor for dynamic access control systems

  • May 1, 2014
  • Bernard Stepien +2 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

XACML is a powerful and flexible access control (AC) policy language. It is an OASIS standard that is now widely used in a variety of applications, particularly those that require inter-operability between AC systems. The language definition includes a precise grammar, syntax, and semantics, and it is both expressive and verbose. This combination of expressive power and verbosity can lead to difficulty in understanding the language's syntax and semantics for both technical and nontechnical users alike. As a result, reducing the difficulty of editing XACML policies has become an intense area of research. In our own work in this area, we previously showed how to render complex XACML conditions using a non-technical display notation and showed that it is easy to use this notation with interactive plain text editors that do not require any technical coding. Although XACML conditions are expressive and flexible, XACML targets are actually the most commonly used XACML language construct. They have an additional level of complexity, especially in version 3.0, due to the fact that the form and kinds of XACML constructs allowed in targets is much more limited. This paper extends our previous work, showing how the same powerful and flexible interactive editing principles can be applied to targets in order to allow users to use natural logic rather than implementation logic. We extend these principles and fully integrate them into our editing tool, easy XACML. This tool is usable by users with no technical knowledge of XACML, thus making XACML totally transparent to the user, while still retaining all of its functionalities and semantics. Our tool thus allows users to focus on policy logic rather than on details of syntax. As a result, the risk of errors in policies is greatly reduced.

Similar Papers
  • Book Chapter
  • Citations2

Policy Management in Cloud

  • Jan 01, 2013
  • Hassan Takabi +1
  • Conference Article
  • Citations4

Verification of Secure Inter-operation Properties in Multi-domain RBAC Systems

  • Jun 01, 2013
  • Antonios Gouglidis +2
  • Research Article
  • Citations5

Modelling and Verifying Dynamic Access Control Policies in Workflow-Based Healthcare Systems

  • Feb 28, 2020
  • Jurnal Kejuruteraan
  • Rokan Uddin Faruqui
  • Research Article
  • Citations2

Distributed access control policies for spectrum sharing

  • Sep 19, 2012
  • Security and Communication Networks
  • Gianmarco Baldini +3
  • Research Article
  • Citations58

Access control and the Resource Description Framework: A survey

  • Dec 06, 2016
  • Semantic Web
  • Sabrina Kirrane +2
  • Conference Article
  • Citations4

Semantically Rich, Context Aware Access Control for Openstack

  • Oct 01, 2018
  • Vishal Rathod +3
  • Research Article
  • Citations12

IPFS based file storage access control and authentication model for secure data transfer using block chain technique

  • Nov 15, 2022
  • Concurrency and Computation: Practice and Experience
  • Mariyaprincy Antony Saviour +1
  • Research Article

Sentry

  • Jun 19, 2010
  • ACM SIGARCH Computer Architecture News
  • Arrvindh Shriraman +1
  • PDF
  • Research Article
  • Citations17

Blowfish Hybridized Weighted Attribute-Based Encryption for Secure and Efficient Data Collaboration in Cloud Computing

  • Jul 11, 2018
  • Applied Sciences
  • Smarajit Ghosh +1
  • Supplementary Content
  • Citations2

Securing Access to Cloud Computing for Critical Infrastructure

  • Jan 01, 2015
  • Liverpool John Moores University
  • Ya Younis
  • Research Article
  • Citations21

A metadata‐based access control model for web services

  • Feb 01, 2005
  • Internet Research
  • Mariemma I Yagüe +2
  • Conference Article
  • Citations1

Flexible Access and Priority Control System Based on 802.1X Authentication in Time of Disaster

  • Jul 01, 2013
  • Toshiki Watanabe +4
  • Research Article
  • Citations3

Access control for network directory systems

  • Aug 01, 1986
  • ACM SIGCOMM Computer Communication Review
  • M Goodwin +1
  • Research Article
  • Citations11

Towards more pro-active access control in computer systems and networks

  • Dec 25, 2014
  • Computers & Security
  • Yixuan Zhang +4
  • Research Article
  • Citations2

A protective mechanism for the access control system in the virtual domain

  • Nov 01, 2016
  • China Communications
  • Jinan Shen +5
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.