DocumentCode :
2322254
Title :
X-STROWL: A generalized extension of XACML for context-aware spatio-temporal RBAC model with OWL
Author :
Que Nguyet Tran Thi ; Tran Khanh Dang
Author_Institution :
Fac. of Comput. Sci. & Technol., HCMC Univ. of Technol., Ho Chi Minh City, Vietnam
fYear :
2012
fDate :
22-24 Aug. 2012
Firstpage :
253
Lastpage :
258
Abstract :
The rapid growth of location-based applications, geographic or large scale information systems has resulted in the demand of strictly controlling data access that requires specifying and enforcing fine grained policies with the variety of context-aware spatial and temporal restrictions. Besides, the interoperable use of distributed and heterogeneous data such as data sharing, data integration or data exchanging between different organizations has caused the formation and development of access control mechanisms using XML for enforcing security rules and policies in accordance with the international standards. In this paper, we propose an extension of XACML called the X-STROWL model for a generalized context-aware role-based access control (RBAC) model with the support of spatio-temporal restrictions and in conformity with the NIST standard for RBAC. In doing this, the XACML architecture is augmented with new functions and data types. In addition, policies are reorganized to adopt with the NIST standard. Besides, a set of conditions aimed to a certain circumstance can be generalized into a context profile and specified in the access control policies. The model also integrates the OWL ontology for semantic reasoning on hierarchical roles to simplify the specification of access control policies and increase the intelligence of the authorization decision engine.
Keywords :
XML; authorisation; data integration; electronic data interchange; knowledge representation languages; open systems; semantic networks; ubiquitous computing; NIST standard; OWL ontology; X-STROWL model; XACML; XML; access control mechanisms; access control policy; authorization decision engine; context profile; context-aware spatial restrictions; context-aware spatio-temporal RBAC model; context-aware temporal restrictions; data access; data exchanging; data integration; data sharing; data types; distributed data; fine grained policy; generalized context-aware role-based access control model; generalized extension; geographic information systems; heterogeneous data; hierarchical roles; international standards; interoperable use; large scale information systems; location-based applications; organizations; security policy; security rules; semantic reasoning; Access control; Context; Context modeling; NIST; OWL; Semantics; RBAC; RBAC with OWL; XACML; access control model; context aware access control model; spatial temporal data access control model;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Digital Information Management (ICDIM), 2012 Seventh International Conference on
Conference_Location :
Macau
ISSN :
pending
Print_ISBN :
978-1-4673-2428-1
Type :
conf
DOI :
10.1109/ICDIM.2012.6360113
Filename :
6360113
Link To Document :
بازگشت