Invention Grant
- Patent Title: Highly parallel evaluation of XACML policies
- Patent Title (中): 高度并行评估XACML策略
-
Application No.: US12123227Application Date: 2008-05-19
-
Publication No.: US08677453B2Publication Date: 2014-03-18
- Inventor: David Chang , Nagaraj Bagepalli , Harsha Narayan , Abhijit Patra
- Applicant: David Chang , Nagaraj Bagepalli , Harsha Narayan , Abhijit Patra
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Techniques for highly parallel evaluation of XACML policies are described herein. In one embodiment, attributes are extracted from a request for accessing a resource including at least one of a user attribute and an environment attribute. Multiple individual searches are concurrently performed, one for each of the extracted attributes, in a policy store having stored therein rules and policies written in XACML, where the rules and policies are optimally stored using a bit vector algorithm. The individual search results associated with the attributes are then combined to generate a single final result using a predetermined policy combination algorithm. It is then determined whether the client is eligible to access the requested resource of the datacenter based on the single final result, including performing a layer-7 access control process, where the network element operates as an application service gateway to the datacenter. Other methods and apparatuses are also described.
Public/Granted literature
- US20090288136A1 HIGHLY PARALLEL EVALUATION OF XACML POLICIES Public/Granted day:2009-11-19
Information query