• DocumentCode
    1845892
  • Title

    Enforcement of Spatial Separation of Duty Constraint

  • Author

    Chen, Weihe ; Tang, Zhu ; Ju, Shiguang

  • Author_Institution
    Dept. of Comput. Sci., Jiangsu Univ., Zhenjiang
  • fYear
    2008
  • fDate
    18-21 Nov. 2008
  • Firstpage
    2108
  • Lastpage
    2114
  • Abstract
    Securing access to data in location-based services and mobile applications pose interesting security requirements against spatially aware access control systems. In particular, the permissions assigned to users depend on their physical positions in a reference space. When a session is established in a spatial regionby users, some spatial constraints related to thissession will be triggered and control the session process during its life automatically. There are often multiple mutually exclusive spatial roles (MESR)constraints that can enforce the same spatial separation of duty policy (SSoD). Although the different MESR constraints can enforce the same effect on the same session, we have found that the different MESR constraints are varying greatly in the enforcement efficiency. The more precise the MESR sets are defined for enforcing an SSoD policy, the less overhead the system is suffered. In this paper, we argue that enforcement of SSoD policies is realized by specifying minimal MESR constraints. By comparing the different MESR constraints which can enforce the same SSoD, we conclude the minimal MESR constraints can avoid redundant restrictiveness effectively and enforce the SSoD policy precisely. We also present an algorithm that generates all minimal MESR constraints that are precise for enforcing oneSSoD policy.
  • Keywords
    authorisation; mobile computing; location-based services; mutually exclusive spatial roles; security requirements; spatial separation of duty policy; spatially aware access control systems; Access control; Application software; Automatic control; Computer science; Data security; Database systems; Information security; Permission; Process control; Spatial databases; Location-based services; mutually exclusive spatial roles; spatial database; spatial region; spatial separation of duty;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Young Computer Scientists, 2008. ICYCS 2008. The 9th International Conference for
  • Conference_Location
    Hunan
  • Print_ISBN
    978-0-7695-3398-8
  • Electronic_ISBN
    978-0-7695-3398-8
  • Type

    conf

  • DOI
    10.1109/ICYCS.2008.223
  • Filename
    4709299