9 Access Control Systems for Geospatial Data and Applications
195
by comprehensive data models, and current developments in standards for geospatial data such as GML [17] are today making possible the development of advanced
ACS that go beyond such naive approaches. However, despite the importance of data
protection, almost no efforts have been devoted to the investigation of access control
models and systems; only very preliminary proposals exist. In order to position current research, in what follows we overview major requirements that arise in access
control for geospatial data.
Richness and Multiplicity of Data Representations
Modern data management systems for geospatial data typically support multiple data
representations (such as attributive, vector-based, and topological representations);
additional representations are also often available, such as raster images. Not only
the same entity may be represented in the data repository according to multiple representations, it can also be represented according to multiple dimensions (such as a
point, 0 dimension, or a region, 2 dimensions). Also geospatial objects may be complex objects, consisting of subobjects. In some cases, one may want to hide some of
the components of a given spatial object. A suitable access control model for geospatial data must thus: (i) Support the specification of authorizations against geospatial
objects at a very fine granularity level. (ii) Account for the various spatial representations. This means that if a user can see an aerial image from which certain objects
have been hidden, it is important that the same objects be hidden from the vectorbased representation of the same area. (iii) Account for the various object dimensions
and resolutions. This means that an administrator should be able to authorize a user to
see a given object at 0 dimension and not at higher dimensions, thus hiding detailed
information about the object shape. Similarly, in a raster representation, the administrator should be able to specify the resolutions according to which certain objects
can be seen. (iv) Support various access rights. In access control models, operations
that can be performed on the protected objects correspond to the access rights. This
allows one to express authorizations in terms of the operations supported by the
model according to which data are represented. It is thus important that in addition
to access rights such as read and write, access rights that correspond to meaningful
operations on geospatial objects be supported.
Dynamic and Mobile User Population
Many of the geospatial applications are characterized by a user population that constantly changes and moves. Also, in many cases, users from different administrative
domains or agencies may need to access the data. A suitable access control model
for geospatial data must thus perform the following: (i) Support attribute-based and
profile-based user specification. Relying on user login names for grant and revoke
authorization is very cumbersome and it is also a low-level approach. Recently,
several attribute-based and profile-based access control mechanisms have been proposed, supported by techniques such as attribute certificates and standards such as
SAML [20]. Also recent extensions to the RBAC model [7] have been developed
Précédent

- 188/317

Suivant