During the last years, policies have become a widespread approach for regulating access to data and managing privacy and security for a large number of multi- agent systems. The increasing amount of data, especially on the Web, requires the definition of more and more complex access norms, and policies seem to provide a suitable solution to this issue. A policy-based approach introduces many important features in access control, as support to dynamic change of policies at run-time, and brings benefits in terms of expressiveness, scalability, efficiency, flexibility, extensi- bility, context-sensitivity and verifiability. The aim of this thesis is to define a unified framework for expressing and en- forcing policies, combining the standard XACML architecture and policy language with the benefits of OWL ontologies and reasoning technologies. A complete cen- tralized architecture has been defined, and a prototype of some of its modules has been successfully developed. A working algorithm for automatically translating XACML policies into corresponding OWL axioms has been defined, together with a complete access decision procedure. Although performance issues have been en- countered, promising solutions have been elaborated in order to make the frame- work suitable to be applied to real environments.

OWL-based representation and enforcement of data access policies

PELLEGRINI, FILIPPO
2014/2015

Abstract

During the last years, policies have become a widespread approach for regulating access to data and managing privacy and security for a large number of multi- agent systems. The increasing amount of data, especially on the Web, requires the definition of more and more complex access norms, and policies seem to provide a suitable solution to this issue. A policy-based approach introduces many important features in access control, as support to dynamic change of policies at run-time, and brings benefits in terms of expressiveness, scalability, efficiency, flexibility, extensi- bility, context-sensitivity and verifiability. The aim of this thesis is to define a unified framework for expressing and en- forcing policies, combining the standard XACML architecture and policy language with the benefits of OWL ontologies and reasoning technologies. A complete cen- tralized architecture has been defined, and a prototype of some of its modules has been successfully developed. A working algorithm for automatically translating XACML policies into corresponding OWL axioms has been defined, together with a complete access decision procedure. Although performance issues have been en- countered, promising solutions have been elaborated in order to make the frame- work suitable to be applied to real environments.
MARFIA, FABIO
ING - Scuola di Ingegneria Industriale e dell'Informazione
29-apr-2015
2014/2015
Tesi di laurea Magistrale
File allegati
File Dimensione Formato  
Tesi.pdf

accessibile in internet solo dagli utenti autorizzati

Descrizione: Testo della tesi
Dimensione 2.24 MB
Formato Adobe PDF
2.24 MB Adobe PDF   Visualizza/Apri

I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10589/107345