发明名称 PROVISIONING ACCESS CONTROL USING SDDL ON THE BASIS OF AN XACML POLICY
摘要 A method is disclosed, and a corresponding data carrier and policy converter, for producing at least one Security Descriptor Definition Language, SDDL, rule from an eXtensible Access Control Markup Language, XACML, policy (P), wherein said at least one SDDL rule is enforceable for controlling access to one or more resources in a computer network. A reverse query is produced indicating a given decision (d), which is one of permit access and deny access, and a set (R) of admissible access requests. Based on the reverse query, the XACML policy (P) and the given decision (d) are translated into a satisfiable logic proposition in Boolean variables (vi, i=1, 2, . . . ) From said ROBDD, variable assignments (RCj=[ARCj1:v1=xj1, ARCj2:v2=xj2, . . . ], j=1, 2, . . . ) satisfying the logic proposition are derived and at least one SDDL rule is created based on said variable assignments (RCj=[ARCj1:v1=xj1, ARCj2:v2=xj2, . . . ], j=1, 2, . . . ) satisfying the logic proposition.
申请公布号 US2015163250(A1) 申请公布日期 2015.06.11
申请号 US201514623311 申请日期 2015.02.16
申请人 AXIOMATICS AB 发明人 Giambiagi Pablo;Rissanen Erik;Spencer Travis
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址 Stockholm SE