• DocumentCode
    2428507
  • Title

    A Semantic Policy Framework for Context-Aware Access Control Applications

  • Author

    Kayes, A.S.M. ; Jun Han ; Colman, Alan

  • Author_Institution
    Fac. of Inf. & Commun. Technol., Swinburne Univ. of Technol., Hawthorn, VIC, Australia
  • fYear
    2013
  • fDate
    16-18 July 2013
  • Firstpage
    753
  • Lastpage
    762
  • Abstract
    Due to the rapid advancement of communication technologies, the ability to support access control to resources in open and dynamic environments is crucial. On the one hand, users demand access to resources and services in an anywhere, anytime fashion. On the other hand, additional challenges arise when ensuring privacy and security requirements of the stakeholders in dynamically changing environments. Conventional Role-based Access Control (RBAC) systems evaluate access permissions depending on the identity/role of the users who are requesting access to resources. However, this approach does not incorporate dynamically changing context information which could have an impact on access decisions in open and dynamic environments. In such environments, an access control model with both dynamic associations of user-role and role-permission capabilities is needed. In order to achieve the above goal, this paper proposes a novel policy framework for context-aware access control (CAAC) applications that extends the RBAC model with dynamic attributes defined in an ontology. We introduce a formal language for specifying our framework including its basic elements, syntax and semantics. Our policy framework uses the relevant context information in order to enable user-role assignment, while using purpose-oriented situation information to enable role-permission assignment. We have developed a prototype to realize the framework and demonstrated the framework through a healthcare case study.
  • Keywords
    authorisation; ubiquitous computing; CAAC applications; RBAC systems; access decisions; access permissions; communication technologies; context aware access control applications; context information; dynamic environments; formal language; healthcare case study; open environments; role based access control; role permission assignment; semantic policy framework; Access control; Context; Context modeling; Hospitals; Mathematical model; Context; Policy Framework; Privacy and Security; Role-Permission Assignment; Situation; User-Role Assignment;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Trust, Security and Privacy in Computing and Communications (TrustCom), 2013 12th IEEE International Conference on
  • Conference_Location
    Melbourne, VIC
  • Type

    conf

  • DOI
    10.1109/TrustCom.2013.91
  • Filename
    6680911