Delegation Management
Abstract
The DoD defines delegation of authority as the action by which a commander assigns part of his authority commensurate with the assigned task to a subordinate commander. While ultimate responsibility cannot be relinquished, delegation of authority carries with it the imposition of a measure of responsibility, the extent of which must be clearly stated. Similarly, access to enterprise services and information can be controlled through delegation of credentials by an authority as established by formal semantics and explicit policies. In this report we describe a prototype system for policy-based access control of web services. Policies, which are written in the Web Ontology Language (OWL), govern both web service access and delegation of authority, and are enforced by IHMC?s KAoS policy services framework and management system. Each delegation of authority policy permits or denies access to a web service based on the credentials of the principal requesting access. A powerful feature of our approach is that it can be applied to existing web services with little or no modification of service implementation. It also allows the schema used for web service design to evolve independently of the policy and domain ontologies.
Document Details
- Document Type
- Technical Report
- Publication Date
- Jul 01, 2011
- Accession Number
- ADA545748
Entities
People
- Jim Jacobs