From: Gerwin Klein <Gerwin.Klein@nicta.com.au>
A new AFP entry is available:
The Unified Policy Framework (UPF)
by Achim D. Brucker, Lukas Brügger, and Burkhart Wolff
Abstract:
We present the Unified Policy Framework (UPF), a generic framework
for modelling security (access-control) policies.q UPF emphasizes
the view that a policy is a policy decision function that grants or
denies access to resources, permissions, etc. In other words,
instead of modelling the relations of permitted or prohibited
requests directly, we model the concrete function that implements
the policy decision point in a system. In more detail, UPF is
based on the following four principles: 1) Functional representation
of policies, 2) No conflicts are possible, 3) Three-valued decision
type (allow, deny, undefined), 4) Output type not containing the
decision only.
http://afp.sf.net/entries/UPF.shtml
Enjoy!
Gerwin
The information in this e-mail may be confidential and subject to legal professional privilege and/or copyright. National ICT Australia Limited accepts no liability for any damage caused by this email or its attachments.
Last updated: Nov 21 2024 at 12:39 UTC