| A general obligation model and continuity: enhanced policy enforcement engine for usage control |
| Full text |
Pdf
(1.74 MB)
|
Source
|
Symposium on Access Control Models and Technologies
archive
Proceedings of the 13th ACM symposium on Access control models and technologies
table of contents
Estes Park, CO, USA
SESSION: Obligations
table of contents
Pages 123-132
Year of Publication: 2008
ISBN:978-1-60558-129-3
|
|
Authors
|
|
Basel Katt
|
University of Innsbruck, Innsbruck, Austria
|
|
Xinwen Zhang
|
Samsung Information Systems America, San Jose, CA
|
|
Ruth Breu
|
University of Innsbruck, Innsbruck, Austria
|
|
Michael Hafner
|
University of Innsbruck, Innsbruck, Austria
|
|
Jean-Pierre Seifert
|
Samsung Information Systems America, San Jose, CA
|
|
| Sponsors |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 20, Downloads (12 Months): 197, Citation Count: 1
|
|
|
ABSTRACT
The usage control model (UCON) has been proposed to augment traditional access control models by integrating authorizations, obligations, and conditions and providing the properties of decision continuity and attribute mutability. Several recent work have applied UCON to support security requirements in different computing environments such as resource sharing in collaborative computing systems and data control in remote platforms. In this paper we identify two individual but interrelated problems of the original UCON model and recent implementations: oversimplifying the concept of usage session of the model, and the lack of comprehensive ongoing enforcement mechanism of implementations. We extend the core UCON model with continuous usage sessions thus extensively augment the expressiveness of obligations in UCON, and then propose a general, continuity-enhanced and configurable usage control enforcement engine. Finally we explain how our approach can satisfy flexible security requirements with an implemented prototype for a healthcare information system.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
{ACF}ITU-T Rec X.812 (1995) | ISO/IEC 10181-3:1996. Security frameworks for open systems: Access control framework. Technical report, 1996.
|
 |
2
|
Agreiter Berthold , Muhammad Alam , Ruth Breu , Michael Hafner , Alexander Pretschner , Jean-Pierre Seifert , Xinwen Zhang, A technical architecture for enforcing usage control requirements in service-oriented architectures, Proceedings of the 2007 ACM workshop on Secure web services, November 02-02, 2007, Fairfax, Virginia, USA
[doi> 10.1145/1314418.1314422]
|
| |
3
|
M. Alam, M. Hafner, M. Memon, and P. Hung. Modeling and enforcing advanced access control policies in healthcare systems with sectet. Mothis, 2007.
|
| |
4
|
|
| |
5
|
|
| |
6
|
Claudio Bettini , Sushil Jajodia , X. Sean Wang , Duminda Wijesekera, Provisions and obligations in policy management and security applications, Proceedings of the 28th international conference on Very Large Data Bases, p.502-513, August 20-23, 2002, Hong Kong, China
|
| |
7
|
|
| |
8
|
|
| |
9
|
|
| |
10
|
M. Hafner, R. Mair, R. Breu, B. Agreiter, S. Unterthiner, and T. Schabetsberger. Health@net. Die verteilte elektronische gesundheitsakte- eine fallstudie in modell-getriebenem security engineering. IT-Sicherheitskongress des BSI, 2007.
|
| |
11
|
M. Hilty, D. Basin, and A. Pretschner. On obligations. In Proc. of European Symposium on Research in Computer Security, 2005.
|
| |
12
|
M. Hilty, A. Pretschner, D. Basin, C. Schaefer, and T. Walter. A policy language for distributed usage control. In Proc. of the 12th European Symposium on Research in Computer Security, 2007.
|
 |
13
|
|
 |
14
|
|
 |
15
|
|
| |
16
|
J. Park, X. Zhang, and R. S. Sandhu. Attribute mutability in usage control. In Proc. of the Annual IFIP WG 11.3 Working Conference on Data and Applications Security,, 2004.
|
 |
17
|
|
| |
18
|
A. Pretschner, M. Hilty, F. Casati, and F. Massacci. Usage control in service-oriented architecture. In Proc. of the 4th Intl. Conf. on Trust, Privacy & Security in Digital Business, 2007.
|
| |
19
|
C. Ribeiro, A. Zuquete, P. Ferreira, and P. Guede. Spl: An access control language for security policies with complex constraints. In Proc. of the Network and Distributed System Security Symposium, 2001.
|
 |
20
|
|
| |
21
|
Reiner Sailer , Xiaolan Zhang , Trent Jaeger , Leendert van Doorn, Design and implementation of a TCG-based integrity measurement architecture, Proceedings of the 13th conference on USENIX Security Symposium, p.16-16, August 09-13, 2004, San Diego, CA
|
| |
22
|
R. Sandhu and J. Park. Usage control: A vision for the next generation access control. Inter. Workshop on Mathematical Methods,Models and Architectures for Computer Networks Security, 2003.
|
 |
23
|
|
 |
24
|
|
| |
25
|
S. Unterthiner, M. Hafner, R.Breu, and T. Schabetsberger. Endpoint security in elga architekturen. eHealth-Medical Informatics meets eHealth. Vienna, 2007.
|
| |
26
|
G. Vogt. Multiple authoriztion- a model and architecture for increased, practical security. In Proc. of IFIP/IEEE Symposium on Integrated Network Management, 2003.
|
| |
27
|
|
 |
28
|
Xinwen Zhang , Masayuki Nakae , Michael J. Covington , Ravi Sandhu, A usage-based authorization framework for collaborative computing systems, Proceedings of the eleventh ACM symposium on Access control models and technologies, June 07-09, 2006, Lake Tahoe, California, USA
[doi> 10.1145/1133058.1133084]
|
 |
29
|
|
CITED BY
|
|
Srijith K. Nair , Andrew S. Tanenbaum , Gabriela Gheorghe , Bruno Crispo, Enforcing DRM policies across applications, Proceedings of the 8th ACM workshop on Digital rights management, October 27-27, 2008, Alexandria, Virginia, USA
|
|