{"title":"Model-driven simulation for cross-domain policy enforcement","authors":"Zhengping Wu, Lifeng Wang","doi":"10.4108/ICST.TRUSTCOL.2010.5","DOIUrl":null,"url":null,"abstract":"This paper proposes an enforcement architecture and develop a simulation framework for cross-domain policy enforcement. The entire simulation environment is used to solve the problem of enforcing policies across domain boundaries when permanent or temporary collaborations have to span over multiple domains. In reality, different systems from different organizations or domains have very different high-level policy representations and various low-level enforcement mechanisms, such as high-level security policies, privacy configurations, and low-level system calls (services). To make sure the compatibility and enforceability of one policy set in another domain, a simulation environment is needed before actual policy deployment and code development. The framework developed in this simulation environment can also be used to generate policy enforcement code directly for permanent integrations or temporary interactions. This framework provides various functions to enforce policies automatically or semi-automatically across domains as by-products. A case study in healthcare information systems confirms the advantages of these new functions and facilities in this simulation environment.","PeriodicalId":354101,"journal":{"name":"6th International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom 2010)","volume":"144 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2010-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"6th International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom 2010)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4108/ICST.TRUSTCOL.2010.5","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
This paper proposes an enforcement architecture and develop a simulation framework for cross-domain policy enforcement. The entire simulation environment is used to solve the problem of enforcing policies across domain boundaries when permanent or temporary collaborations have to span over multiple domains. In reality, different systems from different organizations or domains have very different high-level policy representations and various low-level enforcement mechanisms, such as high-level security policies, privacy configurations, and low-level system calls (services). To make sure the compatibility and enforceability of one policy set in another domain, a simulation environment is needed before actual policy deployment and code development. The framework developed in this simulation environment can also be used to generate policy enforcement code directly for permanent integrations or temporary interactions. This framework provides various functions to enforce policies automatically or semi-automatically across domains as by-products. A case study in healthcare information systems confirms the advantages of these new functions and facilities in this simulation environment.