A method of controlling
enforcement policies (220, 506) for multiple
policy enforcement points, PEPs (208A-N, 310), in a distributed
access control system (202) is provided. The
system operates across various geographic locations, with each PEP positioned at a specific site. The method involves receiving
declaration record messages (210, 302) from each PEP, which include identifiers, locations, protected resources, and enforceable actions (314, 404, 504). Execution
record messages (212, 402, 508) specifying actions to enforce, dependencies (406) between actions, a report (408) on the
action status (410), and conditions (414) determining which PEPs are responsible for
enforcement are also received from each PEP. Each PEP uses these messages to dynamically adjust
enforcement policies to ensure coordinated control over access to
digital data resources. This method helps the
system efficiently
handle access requests, respect action dependencies, and maintain synchronization among PEPs, thereby improving security and consistency across distributed locations. A method of constraining the use of policies of an
access control system (102) which governs an
authorization related to a subject's (104) access to a
digital data resource (106) is provided. The method includes establishing a hierarchy of policies including: (i) a first set of policies defined as governance policies (108, 202, 302), which are used to govern an
authorization during the lifecycle of the
authorization; (ii) a second set of policies defined as authorization policies (110, 204, 304), which manage access rights to the
digital data resource by the subject in the
access control system; and (iii) a third set of policies defined as enforcement policies (112, 206, 306), which specify how decisions and actions related to the access rights are to be enforced by the access
control system. The method includes using the governance policies in the first set of policies in the hierarchy to set constraints on the authorization policies in the second set of policies and on the enforcement policies in the third set of policies, to orchestrate the authorization throughout the lifecycle of the authorization.