The Experts below are selected from a list of 312 Experts worldwide ranked by ideXlab platform

Abdelmalek Benzekri - One of the best experts on this subject based on the ideXlab platform.

  • an adaptive xacmlv3 policy Enforcement Point
    Computer Software and Applications Conference, 2014
    Co-Authors: Romain Laborde, Bashar Kabbani, Francois Barrere, Abdelmalek Benzekri
    Abstract:

    Policies are rules that govern the choices in behavior of a system. Policy based management aims at supporting dynamic adaptability of behavior by changing policy without recoding or stopping the system. The common accepted architecture of such systems includes two main management agents: the Policy Decision Point that analyses requests and set decisions based on a policy and the Policy Enforcement Point (PEP) that enforces the PDP's decision. Modern access control policies include more and more obligations. As a consequence, PEPs must adapt dynamically to enforce them. We propose in this article a dynamically adaptable PEP compliant with XACMLv3 standard.

  • COMPSAC Workshops - An Adaptive XACMLv3 Policy Enforcement Point
    2014 IEEE 38th International Computer Software and Applications Conference Workshops, 2014
    Co-Authors: Romain Laborde, Bashar Kabbani, Francois Barrere, Abdelmalek Benzekri
    Abstract:

    Policies are rules that govern the choices in behavior of a system. Policy based management aims at supporting dynamic adaptability of behavior by changing policy without recoding or stopping the system. The common accepted architecture of such systems includes two main management agents: the Policy Decision Point that analyses requests and set decisions based on a policy and the Policy Enforcement Point (PEP) that enforces the PDP's decision. Modern access control policies include more and more obligations. As a consequence, PEPs must adapt dynamically to enforce them. We propose in this article a dynamically adaptable PEP compliant with XACMLv3 standard.

  • POLICY - PEP = Point to Enhance Particularly
    2008 IEEE Workshop on Policies for Distributed Systems and Networks, 2008
    Co-Authors: Romain Laborde, Francois Barrere, Michel Kamel, Abdelmalek Benzekri
    Abstract:

    Policies are rules that govern the choices in behaviour of a system. Policy based management aims at supporting dynamic adaptability of behaviour by changing policy without receding or stopping the system. The common accepted architecture of such systems includes two main management agents: the policy decision Point that analyses requests and set decisions based on a policy and the policy Enforcement Point that enforces the PDP 's decision. While many works deal with PDP implementations, PEP is considered to be only an interface between applications to be managed and the PDP. PEPs are usually specific to an application and a context of use. As a consequence, they cannot be re-used for new applications and they are implemented from scratch each time. In this article, we present a modular architecture to implement reusable PEPs for policy based authorization systems.

Junliang Chen - One of the best experts on this subject based on the ideXlab platform.

  • access control as a service for public cloud storage
    International Conference on Distributed Computing Systems Workshops, 2012
    Co-Authors: Yang Zhang, Junliang Chen
    Abstract:

    With the rapid application of service-oriented technologies, service and data outsourcing has become a practical and useful computing paradigm. Combined use of access control and cryptography was proposed by many researchers to protect sensitive information in this outsourcing scenario. However, the rigid combination in existing approaches has difficulty in satisfying the flexibility requirement of access control for diverse applications. In this paper, we propose an access control service for public cloud storage, where authorization is controlled by the data owner, and the PDP (Policy Decision Point) and PEP (Policy Enforcement Point) can be securely delegated. In order to implement the service, an attribute-full proxy re-encryption scheme is presented as its corner stone. The other features of our service are as follows: simple key management without the need of key derivation for users to decrypt cipher texts, composing attributes for accessing resources with subject attributes' having inner structures, and authorization relatively separating from encryption. We also give some proofs and analysis of our implementation.

  • ICDCS Workshops - Access Control as a Service for Public Cloud Storage
    2012 32nd International Conference on Distributed Computing Systems Workshops, 2012
    Co-Authors: Yang Zhang, Junliang Chen
    Abstract:

    With the rapid application of service-oriented technologies, service and data outsourcing has become a practical and useful computing paradigm. Combined use of access control and cryptography was proposed by many researchers to protect sensitive information in this outsourcing scenario. However, the rigid combination in existing approaches has difficulty in satisfying the flexibility requirement of access control for diverse applications. In this paper, we propose an access control service for public cloud storage, where authorization is controlled by the data owner, and the PDP (Policy Decision Point) and PEP (Policy Enforcement Point) can be securely delegated. In order to implement the service, an attribute-full proxy re-encryption scheme is presented as its corner stone. The other features of our service are as follows: simple key management without the need of key derivation for users to decrypt cipher texts, composing attributes for accessing resources with subject attributes' having inner structures, and authorization relatively separating from encryption. We also give some proofs and analysis of our implementation.

Romain Laborde - One of the best experts on this subject based on the ideXlab platform.

  • an adaptive xacmlv3 policy Enforcement Point
    Computer Software and Applications Conference, 2014
    Co-Authors: Romain Laborde, Bashar Kabbani, Francois Barrere, Abdelmalek Benzekri
    Abstract:

    Policies are rules that govern the choices in behavior of a system. Policy based management aims at supporting dynamic adaptability of behavior by changing policy without recoding or stopping the system. The common accepted architecture of such systems includes two main management agents: the Policy Decision Point that analyses requests and set decisions based on a policy and the Policy Enforcement Point (PEP) that enforces the PDP's decision. Modern access control policies include more and more obligations. As a consequence, PEPs must adapt dynamically to enforce them. We propose in this article a dynamically adaptable PEP compliant with XACMLv3 standard.

  • COMPSAC Workshops - An Adaptive XACMLv3 Policy Enforcement Point
    2014 IEEE 38th International Computer Software and Applications Conference Workshops, 2014
    Co-Authors: Romain Laborde, Bashar Kabbani, Francois Barrere, Abdelmalek Benzekri
    Abstract:

    Policies are rules that govern the choices in behavior of a system. Policy based management aims at supporting dynamic adaptability of behavior by changing policy without recoding or stopping the system. The common accepted architecture of such systems includes two main management agents: the Policy Decision Point that analyses requests and set decisions based on a policy and the Policy Enforcement Point (PEP) that enforces the PDP's decision. Modern access control policies include more and more obligations. As a consequence, PEPs must adapt dynamically to enforce them. We propose in this article a dynamically adaptable PEP compliant with XACMLv3 standard.

  • POLICY - PEP = Point to Enhance Particularly
    2008 IEEE Workshop on Policies for Distributed Systems and Networks, 2008
    Co-Authors: Romain Laborde, Francois Barrere, Michel Kamel, Abdelmalek Benzekri
    Abstract:

    Policies are rules that govern the choices in behaviour of a system. Policy based management aims at supporting dynamic adaptability of behaviour by changing policy without receding or stopping the system. The common accepted architecture of such systems includes two main management agents: the policy decision Point that analyses requests and set decisions based on a policy and the policy Enforcement Point that enforces the PDP 's decision. While many works deal with PDP implementations, PEP is considered to be only an interface between applications to be managed and the PDP. PEPs are usually specific to an application and a context of use. As a consequence, they cannot be re-used for new applications and they are implemented from scratch each time. In this article, we present a modular architecture to implement reusable PEPs for policy based authorization systems.

Yang Zhang - One of the best experts on this subject based on the ideXlab platform.

  • access control as a service for public cloud storage
    International Conference on Distributed Computing Systems Workshops, 2012
    Co-Authors: Yang Zhang, Junliang Chen
    Abstract:

    With the rapid application of service-oriented technologies, service and data outsourcing has become a practical and useful computing paradigm. Combined use of access control and cryptography was proposed by many researchers to protect sensitive information in this outsourcing scenario. However, the rigid combination in existing approaches has difficulty in satisfying the flexibility requirement of access control for diverse applications. In this paper, we propose an access control service for public cloud storage, where authorization is controlled by the data owner, and the PDP (Policy Decision Point) and PEP (Policy Enforcement Point) can be securely delegated. In order to implement the service, an attribute-full proxy re-encryption scheme is presented as its corner stone. The other features of our service are as follows: simple key management without the need of key derivation for users to decrypt cipher texts, composing attributes for accessing resources with subject attributes' having inner structures, and authorization relatively separating from encryption. We also give some proofs and analysis of our implementation.

  • ICDCS Workshops - Access Control as a Service for Public Cloud Storage
    2012 32nd International Conference on Distributed Computing Systems Workshops, 2012
    Co-Authors: Yang Zhang, Junliang Chen
    Abstract:

    With the rapid application of service-oriented technologies, service and data outsourcing has become a practical and useful computing paradigm. Combined use of access control and cryptography was proposed by many researchers to protect sensitive information in this outsourcing scenario. However, the rigid combination in existing approaches has difficulty in satisfying the flexibility requirement of access control for diverse applications. In this paper, we propose an access control service for public cloud storage, where authorization is controlled by the data owner, and the PDP (Policy Decision Point) and PEP (Policy Enforcement Point) can be securely delegated. In order to implement the service, an attribute-full proxy re-encryption scheme is presented as its corner stone. The other features of our service are as follows: simple key management without the need of key derivation for users to decrypt cipher texts, composing attributes for accessing resources with subject attributes' having inner structures, and authorization relatively separating from encryption. We also give some proofs and analysis of our implementation.

Francois Barrere - One of the best experts on this subject based on the ideXlab platform.

  • an adaptive xacmlv3 policy Enforcement Point
    Computer Software and Applications Conference, 2014
    Co-Authors: Romain Laborde, Bashar Kabbani, Francois Barrere, Abdelmalek Benzekri
    Abstract:

    Policies are rules that govern the choices in behavior of a system. Policy based management aims at supporting dynamic adaptability of behavior by changing policy without recoding or stopping the system. The common accepted architecture of such systems includes two main management agents: the Policy Decision Point that analyses requests and set decisions based on a policy and the Policy Enforcement Point (PEP) that enforces the PDP's decision. Modern access control policies include more and more obligations. As a consequence, PEPs must adapt dynamically to enforce them. We propose in this article a dynamically adaptable PEP compliant with XACMLv3 standard.

  • COMPSAC Workshops - An Adaptive XACMLv3 Policy Enforcement Point
    2014 IEEE 38th International Computer Software and Applications Conference Workshops, 2014
    Co-Authors: Romain Laborde, Bashar Kabbani, Francois Barrere, Abdelmalek Benzekri
    Abstract:

    Policies are rules that govern the choices in behavior of a system. Policy based management aims at supporting dynamic adaptability of behavior by changing policy without recoding or stopping the system. The common accepted architecture of such systems includes two main management agents: the Policy Decision Point that analyses requests and set decisions based on a policy and the Policy Enforcement Point (PEP) that enforces the PDP's decision. Modern access control policies include more and more obligations. As a consequence, PEPs must adapt dynamically to enforce them. We propose in this article a dynamically adaptable PEP compliant with XACMLv3 standard.

  • POLICY - PEP = Point to Enhance Particularly
    2008 IEEE Workshop on Policies for Distributed Systems and Networks, 2008
    Co-Authors: Romain Laborde, Francois Barrere, Michel Kamel, Abdelmalek Benzekri
    Abstract:

    Policies are rules that govern the choices in behaviour of a system. Policy based management aims at supporting dynamic adaptability of behaviour by changing policy without receding or stopping the system. The common accepted architecture of such systems includes two main management agents: the policy decision Point that analyses requests and set decisions based on a policy and the policy Enforcement Point that enforces the PDP 's decision. While many works deal with PDP implementations, PEP is considered to be only an interface between applications to be managed and the PDP. PEPs are usually specific to an application and a context of use. As a consequence, they cannot be re-used for new applications and they are implemented from scratch each time. In this article, we present a modular architecture to implement reusable PEPs for policy based authorization systems.