XACML is being increasingly adopted in large enterprise systems for specifying access control policies. However, the efficient analysis and integration of multiple policies in such large distributed systems still remains a difficult task. In this paper, we propose an annotation technique which is a simple extension to XACML, and may greatly benefit the policy analysis process. We also discuss an important consistency problem during XACML policy translation and point out a few possible research directions.
Citation:
Prathima Rao, Dan Lin, Elisa Bertino, "XACML Function Annotations," policy, pp.178-182, Eighth IEEE International Workshop on Policies for Distributed Systems and Networks (POLICY'07), 2007