Next in thread →
Next in month →
RE: Horn clauses (formerly...access control information)
My basic point is that separation of policy specification from mechanisms for implementing the policy is a good practice - in this particular instance, the mechanism I would have "worried" about would be how to represent the policy in terms of Horn clauses for a specific interpretation system. On a related note, I am still not convinced that an authorization model is strictly necessary to write the policy. I am suspecting our need to use an authorization model is stemming from a sense of "in practice we need PDP to inject new policy statements unstated in the authorization policy." Is this true? Cheers, -Suresh
Next in thread →
Next in month →