Pluggable authorization and distributed enforcement with pam-xacml

Andreas Klenk, Tobias Heide, Benoit Radier, Mikael Salaun, Georg Carle

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Access control is a critical functionality in distributed systems. Services and resources must be protected from unauthorized access. The prevalent practice is that service specific policies reside at the services and govern the access control. It is hard to keep distributed authorization policies consistent with the global security policy of an organization. A recent trend is to unify the different policies in one coherent authorization policy. XACML is a prominent XML standard for formulating authorization rules and for implementing different authorization models. Unifying authorization policies requires an integration of the authorization method with a large application base. The XACML standard does not provide a strategy for the integration of XACML with existing applications. We present pam-xacml, an authorization extension for the Pluggable Authentication Modules (PAM). We argue how existing applications can leverage XACML without modification and state the benefits of using our extended version of the authorization API for PAM. Our experimental results quantify the impact of security and connection establishment of using remote Policy Decision Points (PDP). Our approach provides a method for introducing XACML authorization into existing applications and is an important step towards unified authorization policies.

Original languageEnglish
Title of host publication16. Fachtagung Kommunikation in Verteilten Systemen, KiVS 2009 - Eine Veranstaltung der Gesellschaft fur Informatik (GI) unter Beteiligung der Informationstechnischen Gesellschaft (ITG/VDE)
PublisherKluwer Academic Publishers
Pages253-264
Number of pages12
ISBN (Print)9783540926658
DOIs
StatePublished - 2009
Event16. Fachtagung Kommunikation in Verteilten Systemen, KiVS 2009 - 16th Conference on Communication in Distributed Systems, KiVS 2009 - Kassel, Germany
Duration: 2 Mar 20096 Mar 2009

Publication series

NameInformatik aktuell
ISSN (Print)1431-472X

Conference

Conference16. Fachtagung Kommunikation in Verteilten Systemen, KiVS 2009 - 16th Conference on Communication in Distributed Systems, KiVS 2009
Country/TerritoryGermany
CityKassel
Period2/03/096/03/09

Fingerprint

Dive into the research topics of 'Pluggable authorization and distributed enforcement with pam-xacml'. Together they form a unique fingerprint.

Cite this