atom feed15 messages in org.oasis-open.lists.xacmlRe: [xacml] Agenda for November 15 Te...
FromSent OnAttachments
Carlisle AdamsNov 14, 2001 11:32 am 
Pierangela SamaratiNov 15, 2001 7:09 am 
Pierangela SamaratiNov 15, 2001 7:14 am 
Pierangela SamaratiNov 15, 2001 7:48 am.ps
bill parducciNov 20, 2001 6:15 am 
Pierangela SamaratiNov 26, 2001 11:01 am 
Pierangela SamaratiNov 26, 2001 11:06 am.pdf
Tim MosesNov 27, 2001 5:49 am 
Pierangela SamaratiNov 27, 2001 6:04 am.tex
Hal LockhartNov 27, 2001 6:07 am 
Tim MosesNov 27, 2001 7:05 am 
Pierangela SamaratiNov 27, 2001 7:21 am.tex
Hal LockhartNov 28, 2001 3:16 pm 
bill parducciNov 28, 2001 6:01 pm 
bill parducciNov 29, 2001 7:29 am.bin
Subject:Re: [xacml] Agenda for November 15 Telecon...
From:bill parducci (bi@parducci.net)
Date:Nov 29, 2001 7:29:11 am
List:org.oasis-open.lists.xacml
Attachments:
bin00000.bin - 327k

here is a repost of pierangela's document in pdf format.

b

Pierangela Samarati wrote:

Hi

as mentioned in the concall today al the last policy committee call we discussed the issue of positive (meaning permissions; e.g., "this principal can access this resource") and negative authorizations (meaning denials: "this principal cannot access this resources"). While it is true that you cannot do with permissions alone (many cases call for more flexibility), it is also true that having denials complicates the framework (mostly also since when you start having denials you start thinking of the different semantics that they can carry - and that who specified the rule may have intended).

i had proposed an alternative solution inspired by a recent work, which goes as follows. Distinguish two kinds of rules:

1) the ones that specify sufficient conditions (which are the permissions above)

2) the ones that specify necessary conditions.

instead of repeating descriptions and examples here, i am attaching you a file of that work where the two forms of rules are introduced (Section 4.2). Of course our language is different as more expressive; but that gives the idea.

only one thing, what i call "subject" there is our "principal", what i call "object" is our "resource"

pls just send me email (or post the group) for any clarification that may be needed, and any comments.

best -p