Vis enkel innførsel

dc.contributor.authorUlltveit-Moe, Nils
dc.contributor.authorOleshchuk, Vladimir A
dc.date.accessioned2013-02-01T11:30:51Z
dc.date.available2013-02-01T11:30:51Z
dc.date.issued2012
dc.identifier.citationUlltveit-Moe, N., & Oleshchuk, V. (2012). Decision-cache based XACML authorisation and anonymisation for XML documents. Computer Standards and Interfaces, 34(6), 527-534. doi: 10.1016/j.csi.2011.10.007no_NO
dc.identifier.issn0920-5489
dc.identifier.urihttp://hdl.handle.net/11250/137982
dc.descriptionAuthor's version of an article in the journal: Computer Standards and Interfaces. Also available from the publisher at: http://dx.doi.org/10.1016/j.csi.2011.10.007no_NO
dc.description.abstractThis paper describes a decision cache for the eXtensible Access Control Markup Language (XACML) that supports fine-grained authorisation and anonymisation of XML based messages and documents down to XML attribute and element level. The decision cache is implemented as an XACML obligation service, where a specification of the XML elements to be authorised and anonymised is sent to the Policy Enforcement Point (PEP) during initial authorisation. Further authorisation of individual XML elements according to the authorisation specification is then performed on all matching XML resources, and decisions are stored in the decision cache. This makes it possible to cache fine-grained XACML authorisation and anonymisation decisions, which reduces the authorisation load on the Policy Decision Point (PDP). The theoretical solution is related to a practical case study consisting of a privacy-enhanced intrusion detection system that needs to perform anonymisation of Intrusion Detection Message Exchange Format (IDMEF) XML messages before they are sent to a security operations centre that operates in privacy-preserving mode. The solution increases the scalability of XACML based authorisation significantly, and may be instrumental in implementing federated authorisation and anonymisation based on XACML in several areas, including intrusion detection systems, web services, content management systems and GRID based authentication and authorisation.no_NO
dc.language.isoengno_NO
dc.publisherElsevierno_NO
dc.subjectanonymisationno_NO
dc.subjectauthorisationno_NO
dc.subjectcachingno_NO
dc.subjectprivacy policyno_NO
dc.subjectXACMLno_NO
dc.titleDecision-cache based XACML authorisation and anonymisation for XML documentsno_NO
dc.typeJournal articleno_NO
dc.typePeer reviewedno_NO
dc.subject.nsiVDP::Mathematics and natural science: 400::Information and communication science: 420::Security and vulnerability: 424no_NO
dc.source.pagenumber527-534no_NO
dc.source.volume34no_NO
dc.source.journalComputer Standards and Interfacesno_NO
dc.source.issue6no_NO
dc.identifier.doi10.1016/j.csi.2011.10.007


Tilhørende fil(er)

Thumbnail
Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel