UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

ITU-T - X.1144

(Pre-Published) eXtensible Access Control Markup Language (XACML 3.0)

active, Most Current
Organization: ITU-T
Publication Date: 1 October 2013
Status: active
Page Count: 162
scope:

This Recommendation defines the eXtensible Access Control Markup Language (XACML) Version 3.0. It defines a common language for expressing security policy. The motivation behind XACML is to develop an XML based policy language that can be used: - To provide a method for flexible definition of the procedure by which rules and policies are combined.

- To provide a method for dealing with multiple subjects acting in different capacities.

- To provide a method for basing an authorization decision on attributes of the subject and resource.

- To provide a method for dealing with multi-valued attributes.

- To provide a method for basing an authorization decision on the contents of an information resource.

- To provide a set of logical and mathematical operators on attributes of the subject, resource and environment.

- To provide a method for handling a distributed set of policy components, while abstracting the method for locating, retrieving and authenticating the policy components.

- To provide a method for rapidly identifying the policy that applies to a given action, based upon the values of attributes of the subjects, resource and action.

- To provide an abstraction-layer that insulates the policy-writer from the details of the application environment.

- To provide a method for specifying a set of actions that must be performed in conjunction with policy enforcement.

The core XACML solutions are in this Recommendation. Caluse 7 develops XACML models. Clause 8 develops policy language. Clause 10 develops policy processing rules. Clause 11 develops guidelines for impelementors.

Document History

X.1144
October 1, 2013
(Pre-Published) eXtensible Access Control Markup Language (XACML 3.0)
This Recommendation defines the eXtensible Access Control Markup Language (XACML) Version 3.0. It defines a common language for expressing security policy. The motivation behind XACML is to develop...

References

Advertisement