• DocumentCode
    2099084
  • Title

    Active Authorization Rules for Enforcing RBAC with Spatial Characteristics

  • Author

    Tang, Zhu ; Ju, Shiguang ; Chen, Weihe

  • Author_Institution
    Sch. of Comput. Sci., Jiangsu Univ., Zhenjiang, China
  • Volume
    2
  • fYear
    2008
  • fDate
    20-22 Dec. 2008
  • Firstpage
    632
  • Lastpage
    636
  • Abstract
    The integration of the spatial dimension into RBAC-based models has been the hot topic as a consequence of the growing relevance of geo-spatial information in advanced GIS and mobile applications. Dynamically monitoring the state changes of an underlying system, detecting and reacting to changes without delay are crucial for the success of any access control enforcement mechanism. Thus, current systems or models should provide a flexible mechanism for enforcing RBAC with spatial characteristics in a seamless way, and adapt to policy or role structure changes in enterprises, which are indispensable to make RBAC with spatial characteristics usable in diverse domains. In this paper we will show how On-If-Then-Else authorization rules (or enhanced ECA rules) are used for enforcing RBAC with spatial characteristics in a seamless way. Large enterprises have hundreds of roles, which requires thousands of rules for providing access control, and generating these rules manually is error-prone and a cognitive-burden for non-computer specialists. Thus, in this paper, we will discuss briefly how these authorization rules can be automatically generated from high level specifications of enterprise access control policies.
  • Keywords
    authorisation; On-If-Then-Else authorization rules; RBAC-based models; access control enforcement; active authorization rules; advanced GIS; enterprise access control policies; geo-spatial information; mobile applications; spatial dimension; Access control; Application software; Authorization; Computer science; Computerized monitoring; Delay; Error correction; Geographic Information Systems; Java; Mobile computing; RBAC; access control policies; authorization rules; spatial characteristics;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Science and Computational Technology, 2008. ISCSCT '08. International Symposium on
  • Conference_Location
    Shanghai
  • Print_ISBN
    978-1-4244-3746-7
  • Type

    conf

  • DOI
    10.1109/ISCSCT.2008.311
  • Filename
    4731703