Towards federated policy management
- 2 March 2004
- conference paper
- Published by Institute of Electrical and Electronics Engineers (IEEE)
Abstract
In both data networks and telecommunication networks we are seeing a substantial growth in the number of policy engines and policy-enabled services and applications. We argue that end-users and network operators will need to have a unified, conceptually centralized "view" of the policies that they have specified and a unified understanding of how the policies will play out in the underlying infrastructure. We address the issue of "federated policy management", which allows users to specify preferences and policies at a high level and uses automated tools to map those preferences and policies into appropriate rule sets running on appropriate policy engines. As a key step in this direction, we develop a framework to support federated policy management in a restricted setting. Unlike previous work on distributed rule processing, the focus here is in the context of multiple policy decisions within a single process flow. Specifically, (in the terminology of IETF and Parlay/OSA) we study the case of a service or application that has multiple policy enforcement points (PEPs). We assume a policy language that supports production system style rules with chaining but no recursion (based on previous work on policy requirements for the telecommunications context). We present algorithms whereby users can specify a single coherent ruleset expressing their preferences, and this ruleset is mapped to multiple rulesets, one for each PEP in the application.Keywords
This publication has 8 references indexed in Scilit:
- Towards federated policy managementPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2004
- UCS-Router: a policy engine for enforcing message routing rules in a universal communication systemPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- A community authorization service for group collaborationPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- Policy division and fusion: examples and a method-or, multiple classifiers considered harmfulPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- Have It Your Way: Personalization of Network-Hosted ServicesPublished by Springer Nature ,2002
- The Ponder Policy Specification LanguagePublished by Springer Nature ,2001
- Conflicts in policy-based distributed systems managementIEEE Transactions on Software Engineering, 1999
- Policy hierarchies for distributed systems managementIEEE Journal on Selected Areas in Communications, 1993