Location-based access control systems for mobile users: concepts and research directions

  • Authors:
  • Elisa Bertino;Michael S. Kirkpatrick

  • Affiliations:
  • Purdue University, West Lafayette, IN;James Madison University, Harrisonburg, VA

  • Venue:
  • Proceedings of the 4th ACM SIGSPATIAL International Workshop on Security and Privacy in GIS and LBS
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Many organizations require that sensitive information only be accessed on the organization premises or in secure locations. Access to certain information is thus allowed to authorized users, provided that these users are in specific locations when accessing the information. The GEO-RBAC model addresses such requirement. It is based on the notion of a spatial role, that is, a geographically bounded organizational function. The boundary of a role is defined as a geographical feature, such as a hospital or a classified facility; it specifies the spatial extent in which the user must be located in order to use the role. Besides a physical position obtained from a mobile terminal, users are assigned a logical and device independent position, representing the feature where the user is located. Logical positions are computed from real positions by specific mapping functions. If the user is present within the spatial boundary of a role, the role is said to be enabled. The user is allowed to select (activate) a role and exercise the associated permissions only once the role is enabled. The deployment of an access control system based on GEO-RBAC entails addressing several challenges: (1) access policies may require that access be conditioned not only by the user location but also on the presence or absence of other users; (2) enforcing location-based access control requires making the access control server aware of user locations, which may lead to privacy breaches; (3) trustworthy information about user locations must be obtained. This paper elaborates on these challenges and outlines related research directions.