xacml — archive
RE: [xacml] Agenda for November 15 Telecon...
MHonArc v2.5.2 -->xacml message
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]
Subject: RE: [xacml] Agenda for November 15 Telecon...
- From: Hal Lockhart <[email protected]>
- To: 'bill parducci' <[email protected]>, xacml list <[email protected]>
- Date: Wed, 28 Nov 2001 18:14:21 -0500
Title: RE: [xacml] Agenda for November 15 Telecon...
Bill,
First of all, I have already conceded that we probably need negative rules, so lets not argue about that.
One thing that concerns me about your example is that it is a completely different problem space from any of our use cases. Now I am not trying to disqualify it on a technicality, but I do have a concern that it may represent a problem that is outside of the scope of XACML. Someone (not me of course) might argue that filtering emails is more like doing a text search or a database query than creating a policy model. Can you recast the example in one of the use case problem domains, such as medical records or XML documents? Alternatively, would you like to submit a usecase around filtering SPAM?
For example, your "score" based filtering is outside of anything I had imagined for a policy model.
Your matching fields don't align very well with the current resource/action proposal.
I think (not sure) that you example assumes an order of evaluation. I would prefer to make this explicit, by means of boolean operators and nesting, as Tim as proposed. This makes what is going on clearer to human beings and allows the expresion to be transformed to an equivalent one to optimize the evaluation.
As far as what Pierangela is proposing, my understanding is this.
A necessary condition is and'ed with all other conditions to calculate the result. A sufficient condition is or'ed with all other conditions.
This seems problematic to me, particularly in situations where policies relating to a particular access request are generated by several individials independently. But I have not read her paper completely or thought about it carefully.
Hal
>