Coordination between distributed PDPs

被引:4
作者
Chadwick, David W. [1 ]
Su, Linying [1 ]
Otenko, Oleksandr [1 ]
Laborde, Romain [1 ]
机构
[1] Univ Kent, Comp Lab, Canterbury CT2 7NZ, Kent, England
来源
SEVENTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS | 2006年
关键词
D O I
10.1109/POLICY.2006.14
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
For distributed applications, using a centralised policy decision point (PDP) with a common policy allows coordination between multiple resources that are being accessed. But the central PDP is a bottleneck to performance because every request needs to be diverted to it. Having a set of distributed PDPs co-located with resources can overcome the performance bottleneck, but any form of coordination is then lost. Furthermore, even a centralised PDP sometimes needs to coordinate its access control decision making over time. Therefore, coordination between decision making, for both centralised and distributed PDPs, is needed. This paper addresses issues of coordination between distributed or centralised decision making, by examining when coordination is needed, providing a conceptual model for coordination, defining policy elements that can control coordination, and rules for the refinement of coordination policies The paper provides a detailed example of coordination policy refinement, and provides an outline of how we are implementing the model in our system.
引用
收藏
页码:163 / +
页数:2
相关论文
共 9 条
[1]   A goal-based approach to policy refinement [J].
Bandara, AK ;
Lupu, EC ;
Moffett, J ;
Russo, A .
FIFTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2004, :229-239
[2]  
Bettini C., 2002, Proceedings of the Twenty-eighth International Conference on Very Large Data Bases, P502
[3]  
CHADWICK DW, 2002, IFIP TC11 17 INT C I, P39
[4]  
ELKALAM AA, 2003, IEEE 4 INT WORKSH PO
[5]  
Mints G., 2000, A Short Introduction to Intuitionistic Logic
[6]  
OASIS, EXT ACC CONTR MARK L
[7]   The specification and enforcement of advanced security policies [J].
Ryutov, T ;
Neuman, C .
THIRD INTERNATION WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2002, :128-138
[8]  
SIEBENLIST F, GLOBUSWORLD 2005 7 1
[9]  
Su LY, 2005, SIXTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, P3