|
ABSTRACT
A vital component of any application or environment is security, and yet this is often one of the lower priorities, losing out to performance and functionality issues, if it is considered at all. This paper considers a spatial approach to enabling, understanding and managing access control that is generally applicable across a range of collaborative environments and applications. Access control is governed according to the space within which subjects and objects reside, and the ability to traverse space to get close to an object. We present a framework that enables the SPACE access model [4], previously presented as an access model solely for collaborative virtual environments, to be applied across a number of collaborative systems. This framework is exemplified through mappings of the model to 3D and 2D collaborative environments, namely Spline [1], TeamRooms [19] and Orbit [16]. One particularly interesting feature of the model is the way in which it handles group access by considering how group credentials are determined. These credentials are presented to the model in the usual manner. We conclude by presenting some limitations of our approach, and workarounds.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
|
| |
2
|
Bell, D. E. and LaPadula, L. J., "Secure computer systems: Mathematical foundations", ESD-TR-73-278, Vol.1, ESD/AFSC, Hanscom AFB, Bedford, MA, November 1973.
|
| |
3
|
Bowers, J., "Modelling Awareness and Interaction in Virtual Spaces", in supplement to Proc. 6th MultiG Workshop, Stockholm, Sweden, May 1993.
|
 |
4
|
|
| |
5
|
Bullock A., "SPACE: SPatial Access Control for collaborative virtual Environments", PhD thesis, Department of Computer Science, University of Nottingham, October 1998.
|
| |
6
|
Comic, CSEG at Lancaster University, http ://www.comp.lancs.ac. uk/computing/rese arch/c seg/ comic The COMIC Project {Accessed 29th July 1999}.
|
| |
7
|
Cooper, R., "Organisatiort/Disorganisation", Organisation Studies, 1990.
|
 |
8
|
|
 |
9
|
|
 |
10
|
|
| |
11
|
Fr6con, E. and Stenius, M., "Dive: a scaleable network architecture for distributed virtual environments", Distributed Systems Engineering Journal (5), pp.91- 100, 1998.
|
| |
12
|
Fr6hlich, M., Werner, M., "Demonstration of the interactive Graph Visualization System daVinci", in: R. Tamassia, I. Tollis (Eds.), Proceedings of DIMACS Workshop on Graph Drawing "94, Princeton (USA), 1994, Lecture Notes in Computer Science No. 894; Springer Verlag; January 1995.
|
 |
13
|
|
| |
14
|
Larnpson, B. W., "Protection", in Proc. Fifth Princeton Symposium on Information Sciences and Systems, Princeton University, March 1971, pp. 437--443, reprinted in Operating Systems Review, 8, 1, pp. 18- 24, January 1974.
|
| |
15
|
|
 |
16
|
Tim Mansfield , Simon Kaplan , Geraldine Fitzpatrick , Ted Phelps , Mark Fitzpatrick , Richard Taylor, Evolving Orbit: a process report on building locales, Proceedings of the international ACM SIGGROUP conference on Supporting group work: the integration challenge, p.241-250, November 16-19, 1997, Phoenix, Arizona, United States
[doi> 10.1145/266838.266919]
|
| |
17
|
Neuman, B. C. and Ts'o T., "Kerberos: An Authentication Service for Computer Networks", IEEE Communications, 32(9) pp. 33-38. September 1994.
|
 |
18
|
|
 |
19
|
|
 |
20
|
|
| |
21
|
Sikkel, K., "A Group-based Authorization Model for Cooperative Systems", ECSCW'97, pp. 345-360, Lancaster, UK, September 1997.
|
 |
22
|
|
CITED BY 7
|
|
Ernesto J. Sallés , James Bret Michael , Michael Capps , Don McGregor , Andrzej Kapolka, Security of runtime extensible virtual environments, Proceedings of the 4th international conference on Collaborative virtual environments, p.97-104, September 30-October 02, 2002, Bonn, Germany
|
|
|
Patrice Godefroid , James D. Herbsleb , Lalita Jategaonkar Jagadeesany , Du Li, Ensuring privacy in presence awareness: an automated verification approach, Proceedings of the 2000 ACM conference on Computer supported cooperative work, p.59-68, December 2000, Philadelphia, Pennsylvania, United States
|
|
|
Meredith Ringel , Kathy Ryall , Chia Shen , Clifton Forlines , Frederic Vernier, Release, relocate, reorient, resize: fluid techniques for document sharing on multi-user interactive tables, CHI '04 extended abstracts on Human factors in computing systems, April 24-29, 2004, Vienna, Austria
|
|
|
Joerg M. Haake , Anja Haake , Till Schümmer , Mohamed Bourimi , Britta Landgraf, End-user controlled group formation and access rights management in a shared workspace system, Proceedings of the 2004 ACM conference on Computer supported cooperative work, November 06-10, 2004, Chicago, Illinois, USA
|
|
|
|
|
|
Maurice H. ter Beek , Clarence A. Ellis , Jetty Kleijn , Grzegorz Rozenberg, Team automata for spatial access control, Proceedings of the seventh conference on European Conference on Computer Supported Cooperative Work, p.59-77, September 16-20, 2001, Bonn, Germany
|
|
|
|
|