Showing posts with label XACML. Show all posts
Showing posts with label XACML. Show all posts

Tuesday, August 4, 2009

Kuppinger-Cole: Finally, An Open XACML API

Felix Gaehtgens of Kuppinger-Cole writes about his conversation with Prateek Mishra of Oracle, who indicated that Cisco and Oracle have posted a new XACML API to the OASIS XACML TC.
It was a “soft launch” that was announced at the Kantara meetings on Monday at Burton Catalyst (which very unfortunately, I missed). When Prateek mentioned it to me, it stopped me dead in my tracks, because I find it really significant news – a very important step towards flexible access control policy based on XACML.
Felix's article gives a great example of why Attribute Based Access Control (ABAC) is going to be the next generation of access control and why it will ultimately replace Role Based Access Control (RBAC).

In my opinion, this will be a space to watch closely. RBAC has always been a lot like physical building security guards. They are very good at protected the building entrances and exits; but when it comes to determining who should be able to go where inside the building, or who should be able to interact with whom, the building guard model quickly reaches limits. It is easy to see that one of the enforcement points in security architecture has to be within applications themselves. ABAC and the open XACML API will make this possible.

Sunday, April 13, 2008

OASIS XACML Interop At RSA

Last week, members of the OASIS consortium participated in a interoperability demonstration of XACML. My co-worker, Rich Levinson, was there leading Oracle's participation, along with participants from BEA, IBM, Sun, Axiomatics, Cisco, and the US Department of Veteran Affairs, [correction: and Redhat/JBoss too!].

For me the cool thing was the scenario put forth by Veteran Affairs. It was a scenario that dealt patient health records and privacy (For more info, see Anil Saldhana's write-up.). For me, the really cool thing was when Rich showed me how a patient could block access to a specific doctor, or conversely, a doctor in an emergency room situation could be granted access to patient records. This particular scenario has been one of the primary examples put forward by many government organizations I have spoken with. It was also talked widely by participants of the business requirements review of IGF at Project Liberty.

In fact, when we first talked about a policy language for attribute authorities (back in 2006) to decide how to release personal information, we gravitated quickly towards XACML at Rich Levinson's suggestion. Now, with web policy demonstrating these requirements in an application context at an open interop, it makes the Rich's initial recommendation of basing Attribute Authority Policy Markup Language (AAPML) as a profile of XACML to be right on target!