Title :
Context-based access control for ubiquitous service provisioning
Author :
Corradi, Antonio ; Montanari, Rebecca ; Tibaldi, Daniela
Author_Institution :
DEIS, Bologna Univ., Italy
Abstract :
Pervasive user mobility, wireless connectivity and the widespread diffusion of portable devices raise new challenges for ubiquitous service provisioning. In particular, mobility of users/devices causes frequent and unpredictable changes in physical user location and in consequently available resources and services. Users can also change portable access devices, with different capabilities, even at runtime and during the same service session, thus forcing us to consider very dynamic aspects even due to client heterogeneity. Access control to resources is crucial to leverage the provision of ubiquitous services and calls for novel solutions based on various context information, e.g., user/device location, device properties, user needs, local resource visibility. This work presents a novel access control model built upon the concept of context as the first-class design principle to rule access to resources. As key features, this model allows to associate access control permissions with contexts where users operate and users acquire/lose their permissions when entering/leaving a specific context. Unlike traditional access control solutions where user identity/role triggers policy evaluation when requesting resource access, this model exploits the user context to fully determine the set of available permissions. In addition, the proposed model allows to express context-based access control policies at a high level of abstraction cleanly separate from service logic implementation, thus promoting dynamic policy modification with no impact on the service code. The paper shows the implementation of the proposed model in the UbiCOSM framework and presents a mobile office service provisioning scenario.
Keywords :
biometrics (access control); teleworking; ubiquitous computing; UbiCOSM framework; context-based access control; mobile office service provisioning; pervasive user mobility; ubiquitous service provisioning; wireless connectivity; Access control; Availability; Context modeling; Context-aware services; Logic; Middleware; Permission; Runtime; Teleworking; Wireless networks;
Conference_Titel :
Computer Software and Applications Conference, 2004. COMPSAC 2004. Proceedings of the 28th Annual International
Print_ISBN :
0-7695-2209-2
DOI :
10.1109/CMPSAC.2004.1342877