The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

A Framework for Composition and Enforcement of Privacy-aware and Context-driven Authorization Mechanism for Complex Systems

Download

Download PDF Document
PDF

Author

A M Samuel, M I Sarfraz, H Haseeb and A Ghafoor

Tech report number

CERIAS TR 2011-09

Entry type

techreport

Abstract

Security and privacy of complex systems is a concern due to proliferation of cyber based technologies. Several researchers have pointed out that for the proper enforcement of privacy rules in a complex system, the privacy requirements should be captured in access control systems. In this paper, we present a framework for composition and enforcement of context-aware rules for such systems. The focus of this paper is the design of a system to allow a user (not a system or security administrator) to compose conflict free access control policies for his or her on-line assets. An additional requirement in this case is that such a policy be context-aware. We also present a methodology for verifying the privacy rules to ensure correctness and logical consistency. The verification process is also used to ensure that sensitive security requirements are not violated when privacy rules are enforced.

Download

PDF

Date

2011 – 10 – 19

Key alpha

Samuel

Publication Date

2011-10-19

BibTex-formatted data

To refer to this entry, you may select and copy the text below and paste it into your BibTex document. Note that the text may not contain all macros that BibTex supports.