Access Control for Active Spaces

  • Authors:
  • Geetanjali Sampemane;Prasad Naldurg;Roy H. Campbell

  • Affiliations:
  • -;-;-

  • Venue:
  • ACSAC '02 Proceedings of the 18th Annual Computer Security Applications Conference
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

Active Spaces are physical spaces augmented with heterogeneouscomputing and communication devices along with supportingsoftware infrastructure. This integration facilitates collaborationbetween users, and promotes greater levels of interactionbetween users and devices. An Active Space can be configuredfor different types of applications at different times. We presentan access control system that automates the creation and enforcementof access control policies for different configurations of anActive Space. Our system explicitly recognizes different modes ofcooperation between groups of users, and the dependence betweenphysical and virtual aspects of security in Active Spaces.Our model provides support for both discretionary andmandatory access control policies, and uses role-based accesscontrol techniques for easy administration of users andpermissions. We dynamically assign permissions to user rolesbased on context information. With the help of an examplescenario, we show how we can create dynamic protectiondomains. This allows administrators and application developersthe ability to customize access control policies on a need-to-protectbasis. We also provide a semi-formal specification andanalysis of our model and show how we preserve safety propertiesin spite of dynamic changes to access control permissions. Wealso show how our model preserves the principle of least privilege,promotes separation of duty, and prevents rights-amplification.