xacml — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
Horn clauses (formerly...access control information)
Here are my 2 cents on why I do believe Horn clauses are worth some thought
even though they wouldn't be the best way to represent policy
(Excuse me if I am possibly oversimplifying and butchering
some core ideas here)
When stated in XML, the policy statements can be considered as
a set of axioms. The access control decision (resolution)
can be thought of as proving a theorem such as "Does the subject
have privilege for an action on the target?" The mechanism
for interpreting the policy can be by any computational means.
When stated in Horn clauses, the policy statements can be thought
of as "directly interpretable" axioms - Prolog like systems
can interpret them for you. Now, the access control decision
is a matter of direct interpretation.
Given these, should we consider Horn clauses for policy representation?
Possibly not, because apart from most people not knowing what these are
or how to use these, we should be able to state a policy without
worrying about the mechanism of interpretation of it. I am suspecting that
the policy statements expressed in XML in declarative
style can be more powerful than Horn clauses. It may be interesting
to investigate this question by transforming the policy declarations into
Horn clauses.
If indeed Horn clauses are powerful enough, we can provide them
as yet another means to interpret the policy. Besides, it might be a good
test
bed to answer some of the "what if" questions on policy.
-Suresh
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]