发明名称 METHOD FOR ANALYZING AN XACML POLICY
摘要 XACML (eXtensible Access Control Markup Language) documents, PolicySets and Policies can become long, complex and difficult to completely comprehend. A method is provided for facilitating analysis of such code to make it easier to answer questions such as: Given a particular set of Attribute values (and/or others unknown as of now), what is permitted or denied; are any of the rules redundant; are any of the rules inconsistent; for any pair of policies in the code, what set of Attributes will they both return Permit; how can a policy be refactored into an equivalent set of policies in which each branch of the policy tree pertains to specific values of specified Attributes? To facilitate such analysis and refactoring, every Rule in the collection of policies being analyzed is reduced to an equivalent expression in DNF (Disjunctive Normal Form). Some terms, predicates and other elements may be eliminated.
申请公布号 US2010042973(A1) 申请公布日期 2010.02.18
申请号 US20080190438 申请日期 2008.08.12
申请人 SUN MICROSYSTEMS, INC. 发明人 ANDERSON ANNE H.;PROCTOR SETH T.
分类号 G06F21/00;G06F9/44 主分类号 G06F21/00
代理机构 代理人
主权项
地址