Download D3.3.1 eAuthorisation architecture and platform
Transcript
FP7-ICT 611659 AU2EU 4 Deliverable D3.3.1 Authorization framework architecture This section describes an abstract architecture of the AU2EU authorization framework by giving an overview on each of its components and their role. Section 4.1details the standard XACML components that are provided by the framework. Section 4.2 describes the components that support authorization mapping between various organizations. Section 4.3 describes the components of an extended XACML framework that allow the authorization framework to be integrated with a data-minimization authentication framework and to provide cross-organization dynamic conversion of attributes. 4.1 XACML access control components XACML (eXtensible Access Control Markup Language) is an OASIS standard [2]which defines a flexible attribute-based framework for access control. The standard defines a language for expressing security policy, based on XML. The language defines methods to: combine individual rules and policies into a single policy set that applies to a particular decision request; combine rules and policies; deal with multiple subjects acting in different capacities; base an authorization decision on attributes of the subject and resource; deal with multi-valued attributes; provide a set of logical and mathematical operators on attributes of the subject, resource and environment; specify a set of actions (i.e. obligations) that must be performed in conjunction with policy enforcement. The standard introduces a number of components, mainly: the policy administration point (PAP), i.e. the system entity that creates a policy or policy set; the policy decision point (PDP), i.e. the system entity that evaluates applicable policy and renders an authorization decision; the policy enforcement point (PEP), i.e. the system entity that performs access control, by making decision requests and enforcing authorization decisions; the policy information point (PIP), i.e. the system entity that acts as a source of attribute values; the context handler, i.e. the system entity that converts decision requests in the native request for- mat to the XACML canonical form and converts authorization decisions in the XACML canonical form to the native response format. January 7, 2015 eAuthorization Architecture and Platform Implementation 14