Current architectures and data flow models for accesscontrol are based on request response communication. In stateful or session-based applications monitoring access rights over time this results in polling of author...
详细信息
ISBN:
(数字)9783030397494
ISBN:
(纸本)9783030397494;9783030397487
Current architectures and data flow models for accesscontrol are based on request response communication. In stateful or session-based applications monitoring access rights over time this results in polling of authorization services and for attribute-basedaccesscontrol (ABAC) in the polling of policy information points. This introduces latency or increased load due to polling. attribute-stream-basedaccesscontrol (ASBAC) is an authorization model based on a publish subscribe pattern mitigating these bottlenecks. ASBAC allows the quasi real time consideration of attribute data streams for accesscontrol decisions, such as internet-of-things (IoT) sensor data. This paper introduces the Structure and Agency Policy Language (SAPL) for implementing ASBAC. In addition, the paper describes how ASBAC with SAPL can be implemented by applying a reactive programming model and describes key algorithms for evaluating SAPL policies.
暂无评论