• DocumentCode
    3136184
  • Title

    Access control for Active Spaces

  • Author

    Sampemane, Geetanjali ; Naldurg, Prasad ; Campbell, Roy H.

  • Author_Institution
    Dept. of Comput. Sci., Illinois Univ., Urbana, IL, USA
  • fYear
    2002
  • fDate
    2002
  • Firstpage
    343
  • Lastpage
    352
  • Abstract
    Active Spaces are physical spaces augmented with heterogeneous computing and communication devices along with supporting software infrastructure. This integration facilitates collaboration between users, and promotes greater levels of interaction between users and devices. An Active Space can be configured for different types of applications at different times. We present an access control system that automates the creation and enforcement of access control policies for different configurations of an Active Space. Our system explicitly recognizes different modes of cooperation between groups of users, and the dependence between physical and virtual aspects of security in Active Spaces. Our model provides support for both discretionary and mandatory access control policies, and uses role-based access control techniques for easy administration of users and permissions. We dynamically assign permissions to user roles based on context information. We show how we can create dynamic protection domains. This allows administrators and application developers the ability to customize access control policies on a need-to-protect basis. We also provide a semi-formal specification and analysis of our model and show how we preserve safety properties in spite of dynamic changes to access control permissions.
  • Keywords
    access control; access control; access control policy creation; access control policy enforcement; active spaces; communication devices; computing devices; duty separation; least-privilege principle; rights-amplification prevention; semi-formal specification; software infrastructure; user collaboration; Access control; Application software; Collaboration; Computer science; Hardware; Information security; Permission; Physics computing; Protection; Safety;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2002. Proceedings. 18th Annual
  • ISSN
    1063-9527
  • Print_ISBN
    0-7695-1828-1
  • Type

    conf

  • DOI
    10.1109/CSAC.2002.1176306
  • Filename
    1176306