Policy Administration Control and Delegation using XACML and Delegent

Seitz, Ludwig and Rissanen, Erik and Sandholm, Toumas and Sadighi, Babak and Mulmo, Olle (2005) Policy Administration Control and Delegation using XACML and Delegent. In: Grid 2005 - 6th IEEE/ACM International Workshop on Grid Computing, 13-14 Nov 2005, Seattle, Washington, USA.

Full text not available from this repository.

Official URL: DOI: 10.1109/GRID.2005.1542723


In this paper we present a system permitting controlled policy administration and delegation using the XACML access control system. The need for these capabilities stems from the use of XACML in the SweGrid Accounting System, which is used to enforce resource allocations to Swedish research projects. Our solution uses a second access control system Delegent, which has powerful delegation capabilities. We have implemented limited XML access control in Delegent, in order to supervise modifications of the XML-encoded XACML policies. This allows us to use the delegation capabilities of Delegent together with the expressive access level permissions of XACML.

Item Type:Conference or Workshop Item (Paper)
Additional Information:Published by IEEE Press.
ID Code:271
Deposited By:Vicki Carleson
Deposited On:07 Apr 2008
Last Modified:18 Nov 2009 15:55

Repository Staff Only: item control page