80 likes | 187 Vues
Comparison of DOD NCES, ISO, NIST/OASIS authorization models for SOA management services reveals similar elements. ISO 10181-3 embodies Access Control Information (ACI), though not explicitly defining privacy, deeming it as another policy type. Privacy is managed via Management Services. Harmonization of PASS Authorization in SOA facilitates configuring and provisioning components like ACI installation, modification, revocation, listing, and enabling/disabling components. Explore the OASIS XACML SOA Component for more details.
E N D
Mike Davis PASS Authorization Models
NCES ISO NIST/OASIS Authorization Models for SOA
All have similar elements • PDP=ADF, PEP=AEF, etc • ISO 10181-3 provides sufficient/complete description of Access Control Information (ACI) • Privacy not explicitly described • Privacy is just another type of policy • Privacy is provisioned by Management Services Comparison of Models
Management services configure and provision other components: • Install ACI • Modify ACI • Revoke ACI • List ACI • Disable Component • Enable Component • For a description of other service components see OASIS XACML SOA Component: Management