DocumentCode
2348703
Title
A Context-Risk-Aware Access Control model for Ubiquitous environments
Author
Ahmed, Ali ; Zhang, Ning
Author_Institution
Sch. of Comput. Sci., Univ. of Machester, Oxford
fYear
2008
fDate
20-22 Oct. 2008
Firstpage
775
Lastpage
782
Abstract
This paper reports our ongoing work to design a context-risk-aware access control (CRAAC) model for ubiquitous computing (UbiComp) environments. CRAAC is designed to augment flexibility and generality over the current solutions. Risk assessment and authorization level of assurance play a key role in CRAAC. Through risk assessment, resources are classified into groups according to their sensitivity levels and potential impacts should any unauthorized access occurs. The identified risks are mapped onto their required assurance levels, called object level of assurance (OLoA). Upon receiving an object access request, the requesterpsilas run-time contextual information is assessed to establish a requesterpsilas level of assurance (RLoA) denoting the level of confidence in identifying that requester. The access request is granted if RLoA ges OLoA. This paper describes the motivation for, and the design of, the CRAAC model, and reports a case study of further illustrate the model.
Keywords
authorisation; risk management; ubiquitous computing; authorisation level of assurance; context-risk-aware access control; risk assessment; ubiquitous computing; Access control; Context modeling;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Science and Information Technology, 2008. IMCSIT 2008. International Multiconference on
Conference_Location
Wisia
Print_ISBN
978-83-60810-14-9
Type
conf
DOI
10.1109/IMCSIT.2008.4747331
Filename
4747331
Link To Document