Title :
SACM: Stateful Access Control Model a More Detailed Approach
Author :
dos Santos, Andre L. M. ; Celestino, J. ; Scarlata, Vincent ; Lima, Anderson C. ; Alves, Inacio C. ; di C Sampaio, Davi
Author_Institution :
State Univ. of Ceara, Fortaleza, Brazil
Abstract :
Access control mechanisms are a fundamental building block in the construction of secure computing environments; however, most of the research in this area has been spent on traditional access control needs. These models were sufficient in classical computing systems such as databases and file systems, but as we continue to find new and innovative ways to utilize mobile computing systems these approaches are becoming inadequate. The primary difference between many of these new policies and traditional policies is the need to maintain state across transactions. Currently, systems with these types of needs are controlled by ad-hoc, custom designed systems, rather than a generalized access control model that is able to express them. Traditional models also typically lack the ability to dynamically change. That is, traditional rule sets cannot express policies that require rules to be capable of creating new rules, or deleting old rules. The ability to dynamically produce and delete rules allows for an additional degree of state to be stored in the model. In this paper, we present the Stateful Access Control Model (SACM), which is designed specifically for these new paradigms and provides both these new capabilities. It supports usage in traditional centralized systems where access control information is stored on a computer, as well as a new approach where access rules are distributed across mobile devices. We then exhibit the versatility of this model by expressing a wide range of different types of policies and finished demonstrating the models implementation developed in JAVA.
Keywords :
Java; authorisation; mobile computing; Java; SACM; mobile computing; secure computing; state across transaction; stateful access control model; Authorization; Computational modeling; Data models; Object oriented modeling; Printers; Radiation detectors; Chinese Wall; DACM; Dynamic; Pervasive; Police Language; RBAC; SACM; Security; Stateful; TRBAC;
Conference_Titel :
Computational Science and Engineering (CSE), 2013 IEEE 16th International Conference on
Conference_Location :
Sydney, NSW
DOI :
10.1109/CSE.2013.211