To read this content please select one of the options below:

Towards a flexible framework to support a generalized extension of XACML for spatio-temporal RBAC model with reasoning ability

Tran Khanh Dang (Faculty of Computer Science and Engineering, Ho Chi Minh City University of Technology, VNU-HCM, Ho Chi Minh, Vietnam)
Tuyen Thi Kim Le (Faculty of Computer Science and Engineering, Ho Chi Minh City University of Technology, VNU-HCM, Ho Chi Minh, Vietnam)
Anh Tuan Dang (Faculty of Computer Science and Engineering, Ho Chi Minh City University of Technology, VNU-HCM, Ho Chi Minh, Vietnam)
Ha Duc Son Van (Faculty of Computer Science and Engineering, Ho Chi Minh City University of Technology, VNU-HCM, Ho Chi Minh, Vietnam)

International Journal of Web Information Systems

ISSN: 1744-0084

Article publication date: 10 June 2014

139

Abstract

Purpose

The paper aims to propose a flexible framework to support X-STROWL model. Extensible access control markup language (XACML) is an international standard used for access control in distributed systems. However, XACML and its existing extensions are not sufficient to fulfill sophisticated security requirements (e.g. access control based on user’s roles, context-aware authorizations and the ability of reasoning). Remarkably, X-STROWL, a generalized extension of XACML for spatiotemporal role-based access control (RBAC) model with reasoning ability, is a comprehensive model that overcomes these shortcomings. It mainly focuses on the architecture design as well as the implementation and evaluation of proposed framework and the comparison with others.

Design/methodology/approach

Based on the concept of X-STROWL model, the paper reviewed a large amount of open sources implementing XACML with defined criteria and chose the most suitable framework to be extended for the implementation. The paper also presented a case study used to evaluate the research result.

Findings

Holistic enterprise-ready application security framework – architecture framework (HERAS-AF) is chosen as the most suitable framework to be extended to implement X-STROWL model. Extending HERAS-AF to support spatiotemporal aspect and other contextual conditions as well as the way to integrate security in the access request, together with ability of reasoning for hierarchical roles, are striking features that make the proposed framework able to meet more sophisticated security requirements in comparison with others.

Research limitations/implications

Due to the research content, the performance of proposed framework is not the focused issue of this work.

Originality/value

The proposed framework is a crucial contribution of our research to provide a holistic, extensible and intelligent authorization decision engine.

Keywords

Acknowledgements

This research is partly funded by the Vietnam National University Ho Chi Minh City (VNU-HCM) under grant number B2013-20-02.

Citation

Khanh Dang, T., Thi Kim Le, T., Tuan Dang, A. and Duc Son Van, H. (2014), "Towards a flexible framework to support a generalized extension of XACML for spatio-temporal RBAC model with reasoning ability", International Journal of Web Information Systems, Vol. 10 No. 2, pp. 131-150. https://doi.org/10.1108/IJWIS-12-2013-0037

Publisher

:

Emerald Group Publishing Limited

Copyright © 2014, Emerald Group Publishing Limited

Related articles