The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

GEO-RBAC: A Spatially Aware RBAC

Download

Download PDF Document
PDF

Author

Elisa Bertino, Barbara Catani, Maria Damiani, Paolo Perlasca

Tech report number

CERIAS TR 2006-05

Entry type

article

Abstract

Securing access to data in location-based services and mobile applications requires the definition of spatially aware access control systems. Even if some approaches have already been proposed either in the context of geographic database systems or context-aware applications, a comprehensive framework, general and flexible enough to cope with spatial aspects in real mobile applications, is still missing. In this paper, we make one step towards this direction and we present GEO-RBAC, an extension of the RBAC model to deal with spatial and location-based information. In GEO-RBAC, spatial entities are used to model objects, user positions, and geographically bounded roles. Roles are activated based on the position of the user. Besides a physical position, obtained from a given mobile terminal or a cellular phone, users are also assigned a logical and device independent position, representing the feature (the road, the town, the region) in which they are located. To make the model more flexible and re-usable, we also introduce the concept of role schema, specifying the name of the role as well as the type of the role spatial boundary and the granularity of the logical position. We then extend GEO-RBAC to cope with hierarchies, modeling permission, user, and activation inheritance, and separation of duty constraints. The proposed classes of constraints extend traditional ones to deal with different granularities (schema/instance level) and spatial information. They represent an attempt to define a suitable class of constraints for spatially-aware applications. The paper is concluded with the investigation of several properties concerning the resulting model.

Download

PDF

Date

2006 – 02 – 07

Key alpha

Elisa Bertino

Affiliation

CERIAS Purdue University, DISI University of Genova, DICO University of Milano

Publication Date

2006-02-07

BibTex-formatted data

To refer to this entry, you may select and copy the text below and paste it into your BibTex document. Note that the text may not contain all macros that BibTex supports.