DocumentCode :
3402243
Title :
Enforcing policies in pervasive environments
Author :
Patwardhan, Anand ; Korolev, Vlad ; Kagal, Lalana ; Joshi, Anupam
Author_Institution :
Dept. of Comput. Sci. & Electr. Eng., Maryland Univ., Baltimore, MD, USA
fYear :
2004
fDate :
22-26 Aug. 2004
Firstpage :
299
Lastpage :
308
Abstract :
This work presents an architecture and a proof of concept implementation of a security infrastructure for mobile devices in an infrastructure based pervasive environment. The security infrastructure primarily consists of two parts, the policy engine and the policy enforcement mechanism. Each mobile device within a pervasive environment is equipped with its own policy enforcement mechanism and is responsible for protecting its resources. A mobile device consults the nearest policy server, notifies its current state including its present user, network presence, other accessible devices and location information if available. Using this information the policy server queries the "Rei" engine to dynamically create a policy certificate and issues it to the requesting device. The system wide policy is described in a semantic language "Rei", a lightweight and extensible language which is able to express comprehensive policies using domain specific information. The "Rei" policy engine is able to dynamically decide what rights, prohibitions, obligations, dispensations an actor has on the domain actions. A policy certificate is created and issued to the device. The policy certificate contains a set of granted permissions and a validity period and scope within which the permissions are valid. The policy certificate can be revoked by the policy enforcer based on expiration of the validity period or a combination of timeout, loss of contact with an assigned network. X.509 based public key infrastructure is used to provide identification and authentication.
Keywords :
message authentication; mobile computing; public key cryptography; ubiquitous computing; Rei policy engine; infrastructure based pervasive environment; mobile devices; policy certificate; policy enforcement mechanism; public key infrastructure; security infrastructure; semantic language; Bluetooth; Communication system security; Computer science; Network servers; Permission; Personal digital assistants; Power system security; Protection; Search engines; Wireless communication;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Mobile and Ubiquitous Systems: Networking and Services, 2004. MOBIQUITOUS 2004. The First Annual International Conference on
Print_ISBN :
0-7695-2208-4
Type :
conf
DOI :
10.1109/MOBIQ.2004.1331736
Filename :
1331736
Link To Document :
بازگشت