RE: Thoughts on XACML Policy Model...

From
Tim Moses
Date
2001-08-07T14:04:00+00:00
ID
Thread
RE: Thoughts on XACML Policy Model...
Title:  Thoughts on XACML Policy Model...
Simon - I like your suggestion concerning the best way to  express "sequence".  Perhaps, we could generalize it a  little.  There is at least one other common mechanism for capturing  sequence.  I refer, of course, to "digital signature": if one  signature is within the scope of another signature, then the first signature  must have been applied before the second one .  If we  were to allow your policy statement: "AAA.timestamp <  BBB.timestamp" to be tested by examining the scopes of integrity seals,  such as digital signatures, then we would be able to enforce sequence with a  digital signature infrastructure, as well as with the (at present, much less  common) timestamp infrastructure.

We may  be close to concluding that the RFC 3060 model, with modest extensions, is  suitable for our needs.

Best  regards.  Tim.