A risk calculus extension to the XACML language

1Citations
Citations of this article
17Readers
Mendeley users who have this article in their library.

Abstract

The increase of dynamic cloud computing environments introduces the need for new ways of access control in applications. One access control model which adapts flexibly to such systems on the Internet is the RAdAC (Risk-Adaptive Access Control). This model is based on the user confidence degree and the risk of releasing access to some information taking into account the context in which a request is performed. However, in practice, to use such model it is necessary to implement a technological support as, for example, extending the access control architecture present in the XACML (eXtensible Access Control Markup Language). This paper extends the XACML access control architecture to support the RAdAC model providing a quantitative, concrete and dynamic risk calculus in order to improve the access control in cloud environments. A prototype was developed in Amazon EC2 cloud environment to perform dynamic access control policies using the proposed XACML extension. Some risk calculus tests are described in the paper to exemplify the RAdAC decisions.

Cite

CITATION STYLE

APA

Alves, J., Westphall, C. M., & Schmitt, G. R. (2016). A risk calculus extension to the XACML language. In SBSI 2016 - 12th Brazilian Symposium on Information Systems: Information Systems in the Cloud Computing Era, Proceedings (pp. 321–328). Universidade Federal de Santa Catarina, Florianopolis - UFSC/Departamento de Informatica e Estatistica. https://doi.org/10.5753/sbsi.2016.5978

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free