  • XACML Lite w/REST
  • Why standardization around policies ?
  • Importance of an interchangeable policy format
  • Importance of a standard way to query a policy: PEP (policy enforcement point) is moving inside mobile and web applications - a standard way for policy evaluation would be real useful
  • XACML hard parts: strongly types and difference between single and multi value attributes, 5 return resolution returns, no resource set separation
  • Usefulness in IoT world where multiple device manufacturers and service providers need to inter-operate wrt authorization
  • Challenge: How to deal with multiple policy enforcement points which are not accessible ?
