Policies are rules that govern the choices in behaviour of a system. Policy based management aims at supporting dynamic adaptability of behaviour by changing policy without recoding or stopping the system. The common accepted architecture of such systems includes two main management agents: the Policy Decision Point that analyses requests and set decisions based on a policy and the Policy Enforcement Point that enforces the PDP’s decision. While many works deal with PDP implementations, PEP is considered to be only an interface between applications to be managed and the PDP. PEPs are usually specific to an application and a context of use. As a consequence, they cannot be re-used for new applications and they are implemented from scratch each time. In this article, we present a modular architecture to implement reusable PEPs for policy based authorization systems.
Index Terms:
Policy Based Management, design of PEP
Citation:
Romain Laborde, Michel Kamel, Fran?ois Barr?re, Abdelmalek Benzekri, "PEP = Point to Enhance Particularly," policy, pp.93-96, 2008 IEEE Workshop on Policies for Distributed Systems and Networks, 2008