Download D3.3.1 eAuthorisation architecture and platform

Transcript
FP7-ICT 611659 AU2EU
4
Deliverable D3.3.1
Authorization framework architecture
This section describes an abstract architecture of the AU2EU authorization framework by giving an
overview on each of its components and their role. Section 4.1details the standard XACML components that are provided by the framework. Section 4.2 describes the components that support authorization mapping between various organizations. Section 4.3 describes the components of an extended
XACML framework that allow the authorization framework to be integrated with a data-minimization
authentication framework and to provide cross-organization dynamic conversion of attributes.
4.1 XACML access control components
XACML (eXtensible Access Control Markup Language) is an OASIS standard [2]which defines a
flexible attribute-based framework for access control. The standard defines a language for expressing
security policy, based on XML.
The language defines methods to:
 combine individual rules and policies into a single policy set that applies to a particular decision






request;
combine rules and policies;
deal with multiple subjects acting in different capacities;
base an authorization decision on attributes of the subject and resource;
deal with multi-valued attributes;
provide a set of logical and mathematical operators on attributes of the subject, resource and environment;
specify a set of actions (i.e. obligations) that must be performed in conjunction with policy enforcement.
The standard introduces a number of components, mainly:
 the policy administration point (PAP), i.e. the system entity that creates a policy or policy set;
 the policy decision point (PDP), i.e. the system entity that evaluates applicable policy and renders
an authorization decision;
 the policy enforcement point (PEP), i.e. the system entity that performs access control, by making
decision requests and enforcing authorization decisions;
 the policy information point (PIP), i.e. the system entity that acts as a source of attribute values;
 the context handler, i.e. the system entity that converts decision requests in the native request for-
mat to the XACML canonical form and converts authorization decisions in the XACML canonical
form to the native response format.
January 7, 2015
eAuthorization Architecture and Platform Implementation
14