190
Maria Luisa Damiani and Elisa Bertino
are the spatial data infrastructures (SDI) and location-based services (LBS). An
SDI consists of the technological and organizational infrastructure which enables
the sharing and coordinated maintenance of spatial data among multiple heterogeneous organizations, primarily public administrations, and government agencies. On
the other side, LBS enable mobile users equipped with location-aware terminals to
access information based on the position of terminals. These applications have different requirements on access control. In an SDI, typically, there is the need to account
for various complex structured spatial data that may have multiple representations
across different organizations. In an SDI, the access control is thus object-driven.
Conversely, in LBS, there is the need to account for a dynamic and mobile user population which may request diversified services based on position. Access control is
thus subject-driven or hybrid. However, despite the variety of requirements and the
importance of spatial data protection in these and other applications, very few efforts
have been devoted to the investigation of spatially aware access control models and
systems.
In this chapter, we pursue two main goals: the first is to present an overview of
this emerging research area and in particular of requirements and research directions;
the second is to analyze in more detail some research issues, focusing in particular on
access control in LBS. We can expect LBS to be widely deployed in the near future
when advanced wireless networks, such as mobile geosensor networks, and new positioning technologies, such as the Galileo satellite system will come into operation.
In this perspective, access control will become increasingly important, especially for
enabling selective access to services such as Enterprise LBS, which provide information services to mobile organizations, such as health care and fleet management enterprises. An access control model targeting mobile organizations is GEO-RBAC [4].
Such a model is based on the RBAC (role-based access control) standard and is
compliant with Open Geospatial Consortium (OGC) standards with respect to the
representation of the spatial dimension of the model.
The main contributions of the chapter can be summarized as follows:
• We provide an overview of the ongoing research in the field of spatially aware
access control.
• We show how the spatial dimension is interconnected with the security aspects
in a specific access control model, that is, GEO-RBAC.
• We outline relevant architectural issues related to the implementation of an ACS
based on the GEO-RBAC model. In particular, we present possible strategies for
security enforcement and the architecture of a decentralized ACS for large-scale
LBS applications.
The chapter is organized as follows. The next section provides some background
knowledge on data security and in particular access control models. The subsequent
section presents requirements for geospatial data security and then the state of the art.
Afterward the GEO-RBAC model is introduced. In particular, we present the main
concepts of the model defined in the basic layer of the model, the Core GEO-RBAC.
Hence, architectural approaches supporting GEO-RBAC are presented. Open issues
are finally reported in the concluding section along with directions for future work.
Précédent

- 183/317

Suivant