Transforming XACML policies into database search queries
Jasper Bogaerts, Bert Lagaisse, Wouter Joosen · Lirias · 2017
Application-level access control enforcement of complex policies is suffering from bad performance. This is especially true for search operations when the query results must be filtered by the application according to constraints of access control policies. One approach to reduce this overhead is to incorporate the access control policy in search queries on such data through query rewriting. This poses challenges to what can be expressed as part of such queries when complex policies must be taken into account, especially for expressive policy languages such as XACML. This paper proposes a transformation that converts attribute-based XACML policies to database queries while maintaining original policy semantics. This includes coping with XACML properties such as policy trees and many-valued logic. Our analysis verifies that the transformation leads to equivalent evaluation decisions and that it is a promising step towards policy-based database security.