Affiliation:
1. Karlsruhe Institute of Technology (KIT), Germany
Abstract
Access control in the domain of information system security refers to the process of deciding whether a particular request made by a user to perform a particular operation on a particular object under the control of the system should be allowed or denied. For example, the access control component of a file server might have to decide whether user “Alice” is allowed to perform the operation “delete” on the object “document.txt”. For traditional access control this decision is based on the evaluation of the identity of the user and attributes of the object. The novel idea of location-aware access control is also to consider the user’s current location which is determined by a location system like GPS. The main purpose of this article is to present several approaches for the modeling of location-aware access control rules. We consider generic as well as application-specific access control models that can be found in literature.
Reference45 articles.
1. Aich, S., Sural, S., & Majumdar, A. K. (2007). STARBAC: Spatiotemporal Role Based Access Control. In Proceedings of the 2007 OTM Confederated International Conference “On the move to meaningful internet systems”: CoopIS, DOA, ODBASE, GADA, and IS - Volume Part II, Vilamoura, Portugal (pp. 1567-1582), Berlin, Germany: Springer.
2. Bell, D. E. (2005). Looking back at the Bell-LaPadula Model. In Proceedings of the 21st Annual Computer Security Applications Conference (ACSAC 2005), Tucson, USA (pp. 337-351), Los Alamitos, USA: IEEE Computer Society.
3. Policy Mapper: Administering Location-Based Access-Control Policies
4. Chandran, S. M., & Joshi, J. B. D. (2005). LoT-RBAC: A Location and Time-Based RBAC Model. In Proceedings of the 6th International Conference on Web Information Systems Engineering (WISE '05). New York, USA (pp. 361-375), Berlin, Germany: Springer.
5. Cho, Y., Bao, L., & Goodrich, M. T. (2006). LAAC: A Location-Aware Access Control Protocol. In Proceedings of the Third Annual International Conference on Mobile and Ubiquitous Systems: Networking & Services (MOBIQUITOUS ‘06), San Jose, USA, (pp. 1-7). Los Alamitos, USA: IEEE Computer Society.
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献