xacml — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
RE: [xacml] Modeling Delegation of Rights in a simplified XACML with Haskell
MHonArc v2.5.0b2 -->xacml message
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: RE: [xacml] Modeling Delegation of Rights in a simplified XACML with Haskell
- From: Tim Moses <[email protected]>
- To: "'Frank Siebenlist'" <[email protected]>, "'XACML TC'" <[email protected]>
- Date: Thu, 20 Nov 2003 15:58:20 -0500
Frank - Let me see if I've got this right ... 1. An XACML policy has an identified issuer. 2. Whether or not a subject is permitted to issue a policy can be stated as an XACML policy (I'll call this an intermediate policy), which (in turn) has an identified issuer. The issuer of a policy is treated as the subject in its immediate "upstream" policy. So a chain is formed. Valid chains terminate with the PDP. 3. The subject of an intermediate policy can be identified by name or by any other attribute. 4. The immediate downstream policy in a chain can be identified by name or by its contents using our ResourceAttributeDesignator and ResourceAttributeSelector mechanisms. 5. A combining algorithm will specify how the decisions from each of the policies in a chain are to be combined to produce the ultimate access decision. Obviously, there are other subtleties. But, I wanted to be sure I had this coarse level correct before delving further. Is an action specified in an intermediate policy? What about delegated attributes? Is this outside the scope of your proposal? Don't we need to solve this, too? All the best. Tim.
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]