| From | Sent On | Attachments |
|---|---|---|
| Carlisle Adams | Nov 14, 2001 11:32 am | |
| Pierangela Samarati | Nov 15, 2001 7:09 am | |
| Pierangela Samarati | Nov 15, 2001 7:14 am | |
| Pierangela Samarati | Nov 15, 2001 7:48 am | .ps |
| bill parducci | Nov 20, 2001 6:15 am | |
| Pierangela Samarati | Nov 26, 2001 11:01 am | |
| Pierangela Samarati | Nov 26, 2001 11:06 am | .pdf |
| Tim Moses | Nov 27, 2001 5:49 am | |
| Pierangela Samarati | Nov 27, 2001 6:04 am | .tex |
| Hal Lockhart | Nov 27, 2001 6:07 am | |
| Tim Moses | Nov 27, 2001 7:05 am | |
| Pierangela Samarati | Nov 27, 2001 7:21 am | .tex |
| Hal Lockhart | Nov 28, 2001 3:16 pm | |
| bill parducci | Nov 28, 2001 6:01 pm | |
| bill parducci | Nov 29, 2001 7:29 am | .bin |
| Subject: | Re: [xacml] Agenda for November 15 Telecon... | |
|---|---|---|
| From: | bill parducci (bi...@parducci.net) | |
| Date: | Nov 29, 2001 7:29:11 am | |
| List: | org.oasis-open.lists.xacml | |
| Attachments: | ![]() bin00000.bin - 327k | |
here is a repost of pierangela's document in pdf format.
b
Pierangela Samarati wrote:
Hi
as mentioned in the concall today al the last policy committee call we discussed the issue of positive (meaning permissions; e.g., "this principal can access this resource") and negative authorizations (meaning denials: "this principal cannot access this resources"). While it is true that you cannot do with permissions alone (many cases call for more flexibility), it is also true that having denials complicates the framework (mostly also since when you start having denials you start thinking of the different semantics that they can carry - and that who specified the rule may have intended).
i had proposed an alternative solution inspired by a recent work, which goes as follows. Distinguish two kinds of rules:
1) the ones that specify sufficient conditions (which are the permissions above)
2) the ones that specify necessary conditions.
instead of repeating descriptions and examples here, i am attaching you a file of that work where the two forms of rules are introduced (Section 4.2). Of course our language is different as more expressive; but that gives the idea.
only one thing, what i call "subject" there is our "principal", what i call "object" is our "resource"
pls just send me email (or post the group) for any clarification that may be needed, and any comments.
best -p






.ps