196
Maria Luisa Damiani and Elisa Bertino
supporting access control across different domains; under such an approach, a user
authorized to use a role in a domain is automatically able to enroll in a given role
in another domain. These techniques should certainly be incorporated into an access
control model for geospatial data. (ii) Supporting authorizations that are dynamically enabled or disabled depending on the user location. It is important to notice
that an important requirement is related to the support of mobile users and in particular to the fact that a user may be authorized to access data depending also on the
user location or geographical region. For example, a taxi driver authorized to pick
up passengers only in a given area of Milano cannot access passenger information
when located in another area of the city. It is also important to be able to express
user location in terms of the physical position or the logical position (for example
“being inside of Milano train station”). Addressing such requirement also entails
using secure positioning techniques.
Dynamic Application Contexts
Geospatial data are today increasingly used in various circumstances. For
example, consider some data representing roads in a given region; such data can
be used for planning the road maintenance schedule or for managing an emergency.
It is likely that whether such data may be accessed or not by specific users depend on
the current situation, and it is thus likely that different sets of access control policies
may need to be activated over time, also depending on the occurrence of specific
events. A suitable access control model for geospatial data must thus perform the
following: (i) Support mechanisms for policy grouping and modularization. It is important that security administrators be given mechanisms according to which they
can group policies into modules that are specific for handling specific situations. To
better address compliance requirements, such modules should also include metadata
to provide description and information about the policies inside the various modules.
(ii) Support event-based activation/deactivation of policy modules. This requirement
entails defining an event language and developing suitable event-monitoring techniques. Techniques such as triggers and active rules, developed in the database and
the AI field, could be extended to support the automatic activation/deactivation of
policies. Notice, however, that a crucial issue is represented by techniques providing
high assurance event detection, to avoid an attacker preventing a relevant event from
being reported or injecting a false event.
9.3.2 State of the Art
As we have seen, geospatial applications have challenging requirements of
access control. Yet, such requirements have been only partially addressed by current
research. The spatially aware access control models proposed in literature can be categorized as two broad classes, based on whether they are more focused on geospatial
representation of data or user mobility, which are presented in what follows.
Maria Luisa Damiani and Elisa Bertino
supporting access control across different domains; under such an approach, a user
authorized to use a role in a domain is automatically able to enroll in a given role
in another domain. These techniques should certainly be incorporated into an access
control model for geospatial data. (ii) Supporting authorizations that are dynamically enabled or disabled depending on the user location. It is important to notice
that an important requirement is related to the support of mobile users and in particular to the fact that a user may be authorized to access data depending also on the
user location or geographical region. For example, a taxi driver authorized to pick
up passengers only in a given area of Milano cannot access passenger information
when located in another area of the city. It is also important to be able to express
user location in terms of the physical position or the logical position (for example
“being inside of Milano train station”). Addressing such requirement also entails
using secure positioning techniques.
Dynamic Application Contexts
Geospatial data are today increasingly used in various circumstances. For
example, consider some data representing roads in a given region; such data can
be used for planning the road maintenance schedule or for managing an emergency.
It is likely that whether such data may be accessed or not by specific users depend on
the current situation, and it is thus likely that different sets of access control policies
may need to be activated over time, also depending on the occurrence of specific
events. A suitable access control model for geospatial data must thus perform the
following: (i) Support mechanisms for policy grouping and modularization. It is important that security administrators be given mechanisms according to which they
can group policies into modules that are specific for handling specific situations. To
better address compliance requirements, such modules should also include metadata
to provide description and information about the policies inside the various modules.
(ii) Support event-based activation/deactivation of policy modules. This requirement
entails defining an event language and developing suitable event-monitoring techniques. Techniques such as triggers and active rules, developed in the database and
the AI field, could be extended to support the automatic activation/deactivation of
policies. Notice, however, that a crucial issue is represented by techniques providing
high assurance event detection, to avoid an attacker preventing a relevant event from
being reported or injecting a false event.
9.3.2 State of the Art
As we have seen, geospatial applications have challenging requirements of
access control. Yet, such requirements have been only partially addressed by current
research. The spatially aware access control models proposed in literature can be categorized as two broad classes, based on whether they are more focused on geospatial
representation of data or user mobility, which are presented in what follows.
