• DocumentCode
    693664
  • Title

    Towards enforcing on-the-fly policies in BYOD environments

  • Author

    Costantino, Gianpiero ; Martinelli, F. ; Saracino, Andrea ; Sgandurra, Daniele

  • Author_Institution
    Ist. di Inf. e Telematica, Consiglio Naz. delle Ric., Pisa, Italy
  • fYear
    2013
  • fDate
    4-6 Dec. 2013
  • Firstpage
    61
  • Lastpage
    65
  • Abstract
    The Bring Your Own Device (BYOD) paradigm is becoming extremely popular across all kind of organizations. In fact, employees are continually trying to incorporate their personal devices, e.g. smartphones and tablets, into the office to perform some of their work or simply to access the Internet with a device they trust or they are more familiar with. Unfortunately, several security issues may arise from all these external devices accessing the corporate network. To address these issues, in this paper we propose a framework that enforces on-the-fly instantiated policies inside organizations using trusted BYOD technologies. The proposed framework implements a role-based access control system based upon user identity and her current context. To this end, each user receives a specific policy from a server based upon the current role and context. The effective user identity is confirmed using OAuth 2.0, while the device integrity and policy enforcement is ensured by means of a on-device root-of-trust and an enforcer running on each device.
  • Keywords
    Bring Your Own Device; authorisation; business data processing; mobile computing; trusted computing; Internet access; OAuth 2.0; bring your own device paradigm; corporate network access; device integrity; employee personal devices; on-device root-of-trust; on-the-fly instantiated policies; policy enforcement; role-based access control system; security issues; smartphones; tablets; trusted BYOD technologies; user identity; Authentication; Companies; HTML; Mobile communication; Servers; Switches; BYOD; access control; remote attestation; security policies; trusted enforcement;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance and Security (IAS), 2013 9th International Conference on
  • Conference_Location
    Gammarth
  • Print_ISBN
    978-1-4799-2989-4
  • Type

    conf

  • DOI
    10.1109/ISIAS.2013.6947734
  • Filename
    6947734