在XACML(extensible access control markup language)和其管理性策略草案的基础上,针对目前XACML访问控制框架的特点,提出将XACML策略管理权限判定归结为利用委托策略对一个委托判定请求的判定,使用XML(extensible markup language)模式定义了此委托判定请求语法,描述了将策略管理请求规约为一个委托判定请求的过程,以及根据委托策略进行委托判定请求的判定过程,通过这种方法可以利用委托策略,对策略管理请求是否有效进行判断,从而实现基于扩展XACML的策略管理。
Based on XACML core specification and XACML administrative policy draft, a decision of XACML policy management permission was reduced to a decision of delegation decision request. The delegation decision request schema was defined. It was described that the process of reducing a policy administration request to a delegation decision request and the decision process of delegation decision request. This method can be used to check if a policy administration request is valid and thereby to implement access control policy management based on extended-XACML.