Specify and Enforce the Policies of Quantified Risk Adaptive Access Control

Chen,Weili Han,Jianming Yong
DOI: https://doi.org/10.1109/cscwd.2010.5471991
2010-01-01
Abstract:XACML and its reference implementation can not directly support quantified risk adaptive access control, because there are several special requirements to specify and enforce the policies in risk adaptive access control: the elements in these policies, such as risk, risk level, are not covered; and risk in quantified risk adaptive access control would be mutable, accumulated and required to be continuously controlled. This paper, therefore, extends XACML and its reference implementation to support quantified risk adaptive access control. This paper makes two contributions: design a risk adaptive policy language extended from XACML; and propose a framework to enforce the policies. To the best of our knowledge, this paper is the first research work to discuss this topic.
What problem does this paper attempt to address?