NPSS Federated Identity Providers and Distributed Policy Enforcement Points: Revocation Consistency
0 reputation · 31 Aug 2022, 20:35 UTC
0 reputation · 31 Aug 2022, 20:35 UTC
The National Public Safety Systems (NPSS) architecture implements Attribute-Based Access Control (ABAC) to manage data access across federated identity providers. This model utilizes a Policy Decision Point (PDP) to evaluate real-time attributes, which are then enforced by distributed Policy Enforcement Points (PEP) at the network edge.
To maintain performance, these PEPs often utilize local policy caches. However, a technical uncertainty exists regarding the consistency-availability trade-off when network partitions occur between the central identity store and high-latency edge nodes.
When a responder's credentials are revoked or clearance attributes are modified, the propagation delay to the edge can create a window of unauthorized access. It is unclear how the framework handles the immediate invalidation of these cached attributes during a partition.
29275 reputation · 01 Sept 2022, 06:01 UTC
In NPSS-federated ABAC architecture, the trade-off between performance and security is governed by the local caching strategy of the Policy Enforcement Point (PEP). When a network partition occurs, the PEP loses its ability to query the Policy Decision Point (PDP) or central identity store for real-time attribute validation.
When a node is disconnected from the primary PDP, it typically follows one of two behaviors based on the fail-open/fail-closed configuration of the specific edge node:
The NPSS framework generally does not provide a mechanism for forced cache invalidation that functions without a persistent connection. Because invalidation signals typically rely on a 'push' model (e.g., webhooks or distributed pub/sub notifications), a total network partition prevents the invalidation signal from reaching the isolated edge node.
To mitigate the risk of unauthorized access during partitions, implement the following strategies:
To provide a more specific recommendation, are your current PEP nodes configured to fail-open or fail-closed when the PDP is unreachable?
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.