skip to main content
10.1145/2914642.2914663acmconferencesArticle/Chapter ViewAbstractPublication PagessacmatConference Proceedingsconference-collections
short-paper

Formal Comparison of an Attribute Based Access Control Language for RESTful Services with XACML

Published:06 June 2016Publication History

ABSTRACT

This work introduces RestACL - an access control language for RESTful Services - and compares it with XACML using formal methods. XACML is a generic approach that targets Attribute Based Access Control (ABAC) in general. RestACL is founded on the ideas of the ABAC model, too, but utilizes the concepts of REST enabling a quicker evaluation of access requests. This work gives a brief introduction over the main ideas of RestACL and proves its evidence by giving transformation rules to translate security policies from RestACL to XACML and vice versa. The formalized transformation descriptions show the expressive strength of RestACL, because they demonstrate that any generic ABAC policy written in XACML can be expressed with RestACL, too. The correctness and completeness of RestACL can be proved with the transformation rules, too.

References

  1. Extensible Access Control Markup Language (XACML) Version 3.0. Organization for the Advancement of Structured Information Standards (OASIS), 2013.Google ScholarGoogle Scholar
  2. N. Ammar, E. Bertino, Z. Malik, and A. Rezgui. XACML Policy Evaluation with Dynamic Context Handling. IEEE Transactions on Knowledge and Data Engineering, Volume 27, 2015.Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. J. Crampton and C. Morisset. PTaCL: A Language for Attribute-Based Access Control in Open Systems. POST '12 Proceedings of the First International Conference on Principles of Security and Trust, 2012. Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. T. R. Fielding. Architectural Styles and the Design of Network-based Software Architectures. University of California, Irvine, 2000.Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. M. Hüffmeyer and U. Schreier. Analysis of an Access Control System for RESTful Services. ICWE '16 - International Conference on Web Engineering, 2016.Google ScholarGoogle ScholarCross RefCross Ref
  6. M. Hüffmeyer and U. Schreier. RestACL - An Attribute Based Access Control Language for RESTful Services. ABAC '16 - Proceedings of the 1st Workshop on Attribute Based Access Control, 2016. Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. X. Jin, R. Krishnan, and R. Sandhu. A Unified Attribute-Based Access Control Model Covering DAC, MAC and RBAC. DBSec '12 - Proceedings of the 26th Annual Conference on Data and Applications Security and Privacy, 2012. Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. A. Liu, F. Chen, J. Hwang, and T. Xie. XEngine: A Fast and Scalable XACML Policy Evaluation Engine. SIGMETRICS '08 - Proceedings of the 2008 ACM International Conference on Measurement and Modeling of Computer Systems, 2008. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. M. Masi, R. Pugliese, and F. Tiezzi. Formalisation and Implementation of the XACML Access Control Mechanism. ESSoS '12 Proceedings of the 4th Iinternational Conference on Engineering Secure Software and Systems, 2012. Google ScholarGoogle ScholarDigital LibraryDigital Library
  10. C. Morisset and N. Zannone. Reduction of Access Control Decisions. SACMAT '14 Proceedings of the 19th ACM Symposium on Access Control Models and Technologies, 2014. Google ScholarGoogle ScholarDigital LibraryDigital Library
  11. L. Richardson and M. Amundsen. RESTful Web APIs. O'Reilly Media, 2013. Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. R. Sandhu. The authorization leap from rights to attributes: maturation or chaos? SACMAT '12 - Proceedings of the 17th ACM Symposium on Access Control Models and Technologies, 2012. Google ScholarGoogle ScholarDigital LibraryDigital Library
  13. J. Webber, S. Parastatidis, and I. Robinson. REST in Practice. O'Reilly Media, 2010.Google ScholarGoogle Scholar

Index Terms

  1. Formal Comparison of an Attribute Based Access Control Language for RESTful Services with XACML

          Recommendations

          Comments

          Login options

          Check if you have access through your login credentials or your institution to get full access on this article.

          Sign in
          • Published in

            cover image ACM Conferences
            SACMAT '16: Proceedings of the 21st ACM on Symposium on Access Control Models and Technologies
            June 2016
            248 pages
            ISBN:9781450338028
            DOI:10.1145/2914642

            Copyright © 2016 ACM

            Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

            Publisher

            Association for Computing Machinery

            New York, NY, United States

            Publication History

            • Published: 6 June 2016

            Permissions

            Request permissions about this article.

            Request Permissions

            Check for updates

            Qualifiers

            • short-paper

            Acceptance Rates

            SACMAT '16 Paper Acceptance Rate18of55submissions,33%Overall Acceptance Rate177of597submissions,30%

            Upcoming Conference

            SACMAT 2024

          PDF Format

          View or Download as a PDF file.

          PDF

          eReader

          View online with eReader.

          eReader