Policy evaluation is a process to determine whether a request submitted by a user satisfies the access control policies defined by an organization. Naming heterogeneity between the attribute values of a request and a policy is common due to syntactic variations and terminological variations, particularly among organizations of a distributed environment. Existing policy evaluation engines employ a simple string equal matching function in evaluating the similarity between the attribute values of a request and a policy, which are inaccurate, since only exact match is considered similar. This work proposes several matching functions which are not limited to the string equal matching function that aim to resolve various types of naming heterogeneity. Our proposed solution is also capable of supporting symmetrical architecture applications, in which the organization can negotiate with the users for the release of their resources and properties that raise privacy concerns. The effectiveness of the proposed matching functions on real XACML policies, designed for universities, conference management, and the health care domain, is evaluated. The results show that the proposed solution has successfully achieved higher percentages of Recall and F-measure compared with the standard Sun’s XACML implementation, with our improvement, these measures gained up to 70% and 57%, respectively.
3RK .XDQJ )DFXOW\ RI &RPSXWHU 6FLHQFH DQG ,QIRUPDWLRQ 7HFKQRORJ\ 8QLYHUVLWL 3XWUD 0DOD\VLD 830 6HUGDQJ 6HODQJRU 0DOD\VLD SRKNXDQJ #\DKRR FRP P\ +DPLGDK ,EUDKLP )DFXOW\ RI &RPSXWHU 6FLHQFH DQG ,QIRUPDWLRQ 7HFKQRORJ\ 8QLYHUVLWL 3XWUD 0DOD\VLD 830 6HUGDQJ 6HODQJRU 0DOD\VLD KDPLGDK# IVNWP XSP HGX P\ $%675$&7 5HFHQWO\ UHVHDUFK LV PRUH IRFXVHG RQ VHFXULW\ LQWHJUDWLRQ SROLF\ DQG FRQIOLFW UHFRQFLOLDWLRQ DPRQJ YDULRXV KHDOWKFDUH RUJDQL]DWLRQV +RZHYHU LW LV QHFHVVDU\ WR LGHQWLI\ YDULRXV LQFRQVLVWHQFLHV EHWZHHQ VHFXULW\ SROLFLHV WKURXJK ORJLFDO UHDVRQLQJ DQG WR SURYLGH VXJJHVWLRQ WR VROYH LQFRQVLVWHQFLHV IRU FURVV RUJDQL]DWLRQ FROODERUDWLRQ %HVLGHV WKDW H[LVWLQJ DSSURDFKHV LQ VHFXULW\ SROLF\ LQWHJUDWLRQ DQG FRQIOLFW UHFRQFLOLDWLRQ GLG QRW FRQFHUQ DERXW D VHFXULW\ SULYDF\ DFFHVV FRQWURO PRGHO 7KLV PD\ FDXVH XQDXWKRUL]HG DFFHVV WR VHQVLWLYH LQIRUPDWLRQ LQ HOHFWURQLF PHGLFDO UHFRUGV +HQFH LW LV LPSRUWDQW IRU XV WR LQYHVWLJDWH WKH VHFXULW\ SULYDF\ DFFHVV FRQWURO PRGHO FRQVLGHULQJ WHPSRUDO DQG VSDWLDO FRQWH[W FRQVWUDLQWV LQ RUGHU WR LQWHJUDWH VHFXULW\ SROLFLHV IRU FROODERUDWLRQV DPRQJ RUJDQL]DWLRQV WR WDFNOH VXFK D QHHG ,Q WKLV SDSHU ZH SURSRVH D VHFXULW\ SULYDF\ DFFHVV FRQWURO PRGHO EDVHG RQ UROH EDVHG DFFHVV FRQWURO 5%$& FRQVLGHULQJ WHPSRUDO DQG VSDWLDO FRQWH[W LQ VHFXULW\ SROLFLHV LQWHJUDWLRQ DQG FRQIOLFW UHFRQFLOLDWLRQ %HVLGHV WKDW ZH QHHG WR LQYHVWLJDWH WKH W\SH RI FRQIOLFWV DQG KRZ WR LGHQWLI\ LQFRQVLVWHQFLHV EHWZHHQ SROLFLHV IURP GLIIHUHQW KHDOWKFDUH RUJDQL]DWLRQ FROODERUDWLRQ /RJLFDO UHDVRQLQJ &URVV RUJDQL]DWLRQ FROODERUDWLRQ 6HFXULW\ SROLF\ LQWHJUDWLRQ &RQIOLFW UHFRQFLOLDWLRQ 5ROH %DVHG DFFHVV FRQWURO ,1752'8&7,21 1RZDGD\V KHDOWKFDUH GRPDLQV QHHG WR EH FROODERUDWLYH DQG WR VXSSRUW G\QDPLF DUFKLWHFWXUHV LQ RUGHU WR VKDUH GDWD DPRQJ GLIIHUHQW FURVV RUJDQL]DWLRQ 2IWHQ VXFK GDWD VKDULQJ FRQWDLQV SHUVRQDO FRQILGHQWLDO LQIRUPDWLRQ DERXW D SDWLHQW VXFK DV IDPLO\ FRPSRVLWLRQ DQG '1$ &KDOOHQJLQJ VHFXULW\ DQG SULYDF\ ULVN LVVXHV KDYH DULVHQ GXULQJ VKDULQJ VHQVLWLYH SDWLHQW GDWD LQ GLIIHUHQW ODUJH GLVWULEXWHG DQG KHWHURJHQHRXV RUJDQL]DWLRQV 6HFXULW\ FRQFHUQV RQ FRQILGHQWLDOLW\ LQWHJULW\ DQG DYDLODELOLW\ RI SDWLHQW GDWD 3ULYDF\ W\SLFDOO\ FRQFHUQV WKH SDWLHQW ULJKW WR NHHS WKHLU SHUVRQDO PHGLFDO UHFRUGV 7KXV VHFXULW\ FDQ EH VHHQ DV D NH\ WR SULYDF\ DV D QHFHVVDU\ FRQGLWLRQ WR DVVXUH LW 6HFXULW\ SULYDF\ DFFHVV FRQWURO IRFXVHV RQ GDWD VKDULQJ LQ FURVV RUJDQL]DWLRQ (DFK RUJDQL]DWLRQ PD\ VSHFLI\ LWV RZQ VHFXULW\ SROLFLHV LQGHSHQGHQWO\ 'DWD VKDULQJ FDUULHV RXW WKH SROLF\ LQWHJUDWLRQ DPRQJ GLIIHUHQW FURVV RUJDQL]DWLRQ FROODERUDWLRQV +RZHYHU YDULRXV LQFRQVLVWHQFLHV EHWZHHQ DFFHVV SROLFLHV IURP GLIIHUHQW KHDOWKFDUH XQLWV PD\ RFFXU GXULQJ LQWHJUDWLRQ +HQFH LW LV QHFHVVDU\ WR LQYHVWLJDWH SROLF\ FRQVLVWHQF\ WKURXJK ORJLFDO UHDVRQLQJ DQG FRQIOLFW UHFRQFLOLDWLRQ IRU SROLF\ LQFRQVLVWHQFLHV EHIRUH D VHFXULW\ SROLF\ FDQ EH LQWHJUDWHG IRU KHDOWKFDUH FROODERUDWLRQ 5HFHQWO\ UHVHDUFK LV PRUH IRFXVHG RQ VHFXULW\ SROLFLHV LQWHJUDWLRQ DQG FRQIOLFW UHFRQFLOLDWLRQ DPRQJ YDULRXV KHDOWK FDUH RUJDQL]DWLRQV +RZHYHU LW LV QHFHVVDU\ WR LGHQWLI\ YDULRXV LQFRQVLVWH...
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.
customersupport@researchsolutions.com
10624 S. Eastern Ave., Ste. A-614
Henderson, NV 89052, USA
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Copyright © 2025 scite LLC. All rights reserved.
Made with 💙 for researchers
Part of the Research Solutions Family.