Multi-data-types Interval Decision Diagrams for XACML Evaluation Engine

Authors
Publication date 2013
Host editors
  • J. Castellà-Roca
  • J. Domingo-Ferrer
  • J. Garcia-Alfaro
  • A.A. Ghorbani
  • C.D. Jensen
  • J.A. Manjón
  • I.V. Onut
  • N. Stakhanova
  • V. Torra
  • J. Zhang
Book title 2013 Eleventh Annual International Conference on Privacy, Security and Trust: Universitat Rovira i Virgili, Tarragona, Catalonia, July 10-12, 2013
ISBN
  • 9781467358392
Event 2013 Eleventh Annual International Conference on Privacy, Security and Trust
Pages (from-to) 257-266
Publisher Piscataway, NJ: IEEE
Organisations
  • Faculty of Science (FNWI) - Informatics Institute (IVI)
Abstract
XACML policy evaluation efficiency is an important factor influencing the overall system performance, especially when the number of policies grows. Some existing approaches on high performance XACML policy evaluation can support simple policies with equality comparisons and handle requests with well defined conditions. Such mechanisms do not provide the semantic correctness of combining algorithms in cases with indeterminate and not-applicable states. They ignore the critical attribute setting, a mandatory property in XACML, leading to potential missing attribute attacks. In this paper, we present a solution using data interval partition aggregation together with new decision diagram combinations, that not only optimizes the performance but also provides correctness and completeness of XACML 3.0 features, including complex logical expressions, correctness in indeterminate states processing, critical attribute setting, obligations and advices as well as complex comparison functions for multiple data types.
Document type Conference contribution
Language English
Published at https://doi.org/10.1109/PST.2013.6596061
Permalink to this page
Back