Title: Thoughts on XACML Policy Model...
Simon - I like your suggestion concerning the best way to express "sequence". Perhaps, we could generalize it a little. There is at least one other common mechanism for capturing sequence. I refer, of course, to "digital signature": if one signature is within the scope of another signature, then the first signature must have been applied before the second one . If we were to allow your policy statement: "AAA.timestamp < BBB.timestamp" to be tested by examining the scopes of integrity seals, such as digital signatures, then we would be able to enforce sequence with a digital signature infrastructure, as well as with the (at present, much less common) timestamp infrastructure.
We may be close to concluding that the RFC 3060 model, with modest extensions, is suitable for our needs.
Best regards. Tim.