Research on the Policy Definition in the Attribute Based Access Control

葛琨,郎波
DOI: https://doi.org/10.3969/j.issn.1008-0570.2008.33.003
2008-01-01
Abstract:Attribute Based Access Control(ABAC)is a new access control method in the application of Web Service.eXtensible Ac-cess Control Markup Language(XACML)is an important standard supporting ABAC;it brings up an ABAC policy enforcing architec-ture and an ABAC policy definition method.But it is very complicated to define ABAC policy using XACML,and It is difficult for common user to master it.In this paper,we analyze the definition method in XACML based on the ABAC model,bring up a XACML based policy definition template and the policy definition method based on it.In this way,we can both assure the accurate of the policy and simplify the policy definition procedure.
What problem does this paper attempt to address?