OASIS Open Mailing List Archives  ·  All Lists  ·  xacml  ·  2001-06

xacml — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Horn clauses (formerly...access control information)


Here are my 2 cents on why I do believe Horn clauses are worth some thought even though they wouldn't be the best way to represent policy (Excuse me if I am possibly oversimplifying and butchering some core ideas here) When stated in XML, the policy statements can be considered as a set of axioms. The access control decision (resolution) can be thought of as proving a theorem such as "Does the subject have privilege for an action on the target?" The mechanism for interpreting the policy can be by any computational means. When stated in Horn clauses, the policy statements can be thought of as "directly interpretable" axioms - Prolog like systems can interpret them for you. Now, the access control decision is a matter of direct interpretation. Given these, should we consider Horn clauses for policy representation? Possibly not, because apart from most people not knowing what these are or how to use these, we should be able to state a policy without worrying about the mechanism of interpretation of it. I am suspecting that the policy statements expressed in XML in declarative style can be more powerful than Horn clauses. It may be interesting to investigate this question by transforming the policy declarations into Horn clauses. If indeed Horn clauses are powerful enough, we can provide them as yet another means to interpret the policy. Besides, it might be a good test bed to answer some of the "what if" questions on policy. -Suresh

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]