A Framework to Enforce Access Control, Usage Control and Obligations
نویسندگان
چکیده
In this paper, we define a core language to express access control, usage control and obligation policies and we specify a policy controller in charge of evaluating such policies. This policy language can be used to specify security requirements of many applications such as DRM (Digital Right Management), P2P or Web Service applications. It is used to express both contextual permissions and obligations. In our formalism, a permission is associated with two conditions: The “start condition” that must be true just when the access request is evaluated (access control) and the “ongoing condition” that must be always satisfied while the access is in progress (usage control). Moreover, we introduce the concept of cancellation ac tions to authorize users to cancel access in progress. Obligations are mandatory access that users must perform. An obligation is associated with two conditions as well: The “raise condition” to trigger the obligation and the “deadline condition” to determine when the obligation is violated. Moreover, we introduce the concept of non-persistent obligation where the raise condition must be true until the corre sponding request is received or the deadline expires, otherwise the corresponding access is no longer mandatory.
منابع مشابه
Unifying Access and Resource Usage Control over Standard Client-Server Interactions
We propose a novel framework for integrated access and resource usage control over standard client server interactions. Historically, access control has been developed without considering resource usage. Resource control has thus developed as an ad hoc server-centric set of mechanisms (e.g., file system quota, network bandwidth quote, etc.). We believe that resource usage control is strongly re...
متن کاملA centralized privacy-preserving framework for online social networks
There are some critical privacy concerns in the current online social networks (OSNs). Users' information is disclosed to different entities that they were not supposed to access. Furthermore, the notion of friendship is inadequate in OSNs since the degree of social relationships between users dynamically changes over the time. Additionally, users may define similar privacy settings for their f...
متن کاملObligation Language for Access Control and Privacy Policies
Defining and enforcing obligations are key aspects of privacy protection. Most of today’s access control and data handling languages recognize the importance of obligations and even provide extension points but lack concrete language constructs to actually express obligations. This position paper proposes requirements for a general obligation language spanning access control and usage control. ...
متن کاملThe ABC Core Model for Usage Control: Integrating Authorizations, oBligations, and Conditions
In this paper, we introduce the family of ABC (Authorizations, oBligations, and Conditions) models for usage control (UCON). We call these core models because they address the essence of usage control, leaving administration, delegation and other important but second-order issues for later work. The term usage control is a generalization of access control to cover obligations, conditions, conti...
متن کاملExtending HP Identity Management Solutions to Enforce Privacy Policies and Obligations for Regulatory Compliance by Enterprises
This paper describes issues and requirements related to privacy management as an aspect of improved governance in enterprises. It focuses on the privacy enforcement aspect, in particular related to privacy-aware access control and enforcement of privacy obligations: this is still a green field and, at the same time, is a key aspect to be taken into account to ensure compliance both with regulat...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Annales des Télécommunications
دوره 62 شماره
صفحات -
تاریخ انتشار 2007