NPSS Federated Identity Providers and Distributed Policy Enforcement Points: Revocation Consistency
29K reputation · 31 Aug 2022, 20:35 UTC
Consistency in Distributed Policy Enforcement
The National Public Safety Systems (NPSS) architecture implements Attribute-Based Access Control (ABAC) to manage data access across federated identity providers. This model utilizes a Policy Decision Point (PDP) to evaluate real-time attributes, which are then enforced by distributed Policy Enforcement Points (PEP) at the network edge.
To maintain performance, these PEPs often utilize local policy caches. However, a technical uncertainty exists regarding the consistency-availability trade-off when network partitions occur between the central identity store and high-latency edge nodes.
When a responder's credentials are revoked or clearance attributes are modified, the propagation delay to the edge can create a window of unauthorized access. It is unclear how the framework handles the immediate invalidation of these cached attributes during a partition.
- What is the documented behavior for credential revocation at the PEP when the node is disconnected from the primary PDP?
- Does the NPSS framework provide a mechanism for forced cache invalidation across federated boundaries that does not rely on a persistent connection?