Attribute Based Access Control is a widely used access control model, which regulates the access to the resources by evaluating security policies which contain a number of attributes related to the subject, the object and the environment distinguishing thus from a simple access control list or a role-based model. Although, the dynamicity of today's environments requires security policies that consider a large set of attributes and conditions, making thus the policy writing an error-prone procedure. Existing policy editors are usually targeted to one particular framework and satisfy the needs of this application environment without providing the possibility of a more general use. In this paper we provide a comparison among the most known ABAC policy editors and their characteristics. Moreover, we propose an extension of one of those editors aiming at providing a more general and simple environment which supports the definition not only of attribute based access control policies, but also for Usage Control policies.

A Comparison Among Policy Editors for Attributed Based Access Control Model

Martinelli F;Osliak O;
2020

Abstract

Attribute Based Access Control is a widely used access control model, which regulates the access to the resources by evaluating security policies which contain a number of attributes related to the subject, the object and the environment distinguishing thus from a simple access control list or a role-based model. Although, the dynamicity of today's environments requires security policies that consider a large set of attributes and conditions, making thus the policy writing an error-prone procedure. Existing policy editors are usually targeted to one particular framework and satisfy the needs of this application environment without providing the possibility of a more general use. In this paper we provide a comparison among the most known ABAC policy editors and their characteristics. Moreover, we propose an extension of one of those editors aiming at providing a more general and simple environment which supports the definition not only of attribute based access control policies, but also for Usage Control policies.
2020
Istituto di informatica e telematica - IIT
: Policy Editors
ABAC
Apache Hadoop
Amazon Web Services
XACML
File in questo prodotto:
File Dimensione Formato  
prod_440727-doc_158139.pdf

accesso aperto

Descrizione: A Comparison Among Policy Editors for Attributed Based Access Control Model
Tipologia: Versione Editoriale (PDF)
Licenza: Nessuna licenza dichiarata (non attribuibile a prodotti successivi al 2023)
Dimensione 789.14 kB
Formato Adobe PDF
789.14 kB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/424944
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact