A general obligation model and continuity: enhanced policy enforcement engine for usage control

  • Authors:
  • Basel Katt;Xinwen Zhang;Ruth Breu;Michael Hafner;Jean-Pierre Seifert

  • Affiliations:
  • University of Innsbruck, Innsbruck, Austria;Samsung Information Systems America, San Jose, CA;University of Innsbruck, Innsbruck, Austria;University of Innsbruck, Innsbruck, Austria;Samsung Information Systems America, San Jose, CA

  • Venue:
  • Proceedings of the 13th ACM symposium on Access control models and technologies
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

The usage control model (UCON) has been proposed to augment traditional access control models by integrating authorizations, obligations, and conditions and providing the properties of decision continuity and attribute mutability. Several recent work have applied UCON to support security requirements in different computing environments such as resource sharing in collaborative computing systems and data control in remote platforms. In this paper we identify two individual but interrelated problems of the original UCON model and recent implementations: oversimplifying the concept of usage session of the model, and the lack of comprehensive ongoing enforcement mechanism of implementations. We extend the core UCON model with continuous usage sessions thus extensively augment the expressiveness of obligations in UCON, and then propose a general, continuity-enhanced and configurable usage control enforcement engine. Finally we explain how our approach can satisfy flexible security requirements with an implemented prototype for a healthcare information system.