This page (revision-1) was last changed on 29-Nov-2024 16:16 by UnknownAuthor

Only authorized users are allowed to rename pages.

Only authorized users are allowed to delete pages.

Page revision history

Version Date Modified Size Author Changes ... Change note

Page References

Incoming links Outgoing links

Version management

Difference between version and

At line 1 added 27 lines
!!! Overview
[{$pagename}] or [PDP] evaluates [Access Requests] against the digital representation of the [Authorization] [Policies|Policy] from the [Policy Retrieval Point] along with [data] from the [Policy Information Point] before issuing [access] decisions.
Obviously in some systems, all of the entities:
* [Policy Retrieval Point]
* [Policy Information Point]
* [Policy Decision Point]
* [Policy Enforcement Point]
May reside within the same [application] of the same host.
! [RFC 2753]
Policy Decision Point (PDP): The point where policy decisions are made.
! [XACML]
The system entity that evaluates applicable policy and renders an authorization decision. This term is defined in a joint effort by the [IETF] Policy Framework Working Group and
the [Distributed Management Task Force] ([DMTF])/[Common Information Model] ([CIM]) in [RFC 3198]. This term corresponds to "Access Decision Function" (ADF) in (ISO10181-3).
The [OASIS] [XACML] standard defines [Policy Decision Point] and its implementation using the [XACML] language.
! [NIST]
The concept of [{$pagename}] (also known as Access Control Decision Function) is a locus where policy rules have been resolved, evaluated, and combined to yield a binary value for interpretation by a [Policy Enforcement Point].
! Generic
[{$pagename}] is a component of [Policy Based Management System]. When an [entity] performs an [Access Request] for [resource] on a network that uses [Policy Based Management System], the [Policy Information Point] will describe the [entity]'s [attributes] to other entities on the system. The [{$pagename}] has the job of deciding whether or not to authorize the user based on the description of the entity's attributes. Applicable policies are stored on the system and are analyzed by the [{$pagename}]. The [{$pagename}] makes it's decision and returns the decision. The [Policy Enforcement Point] will let the [entity] know whether or not he has been authorized to access the requested resource.
!! More Information
There might be more information for this subject on one of the following:
[{ReferringPagesPlugin before='*' after='\n' }]