9 Access Control Systems for Geospatial Data and Applications
197
Access Control for Geospatial Data
The first access control model for geographical data has been proposed [1] to
control the access to georeferenced Earth images. The purpose of such an approach
is the controlled dissemination of satellite images at different levels of resolution
through a DAC policy. In particular, authorizations state which images users are allowed to access and at which resolution. The system, however, is limited in that it
only deals with satellite images. To overcome these limitations, an ACS has been
recently developed for the protection of vector-based data available on Web [5]. The
underlying model is simple but anticipates some ideas that have been more extensively developed by GEO-RBAC. The central concept in such model is that of spatial
authorization. A spatial authorization is defined by the tuple < u, f t, p, w >, where
u denotes the user, f t the object specified in terms of spatial feature types (such as
building or house), p the operation in the form of Web service to be performed on
spatial objects of the specified type (such as InsertOb ject, to introduce a new spatial
element), and w is the authorization window. The authorization window indicates
the geographical scope of the authorization, that is, the portion of space in which the
authorization applies. Accordingly, one can state, for example, that user u is allowed
to carry out operation p on all objects of type f t located in the authorization window
w. Furthermore, the model supports the specification of administrative functions for
the creation and update of spatial authorizations based on a decentralized administration policy. The notion of authorization window has also been integrated in a
different access control model, which has been developed for regulating the access
to a spatial database [2]. The peculiarity of this approach is that the database is based
on a complex spatial data model, enabling multiple levels of spatial representation
at multiple granularities. The access control model thus enables the specification of
which objects at which granularity and in which portion of space can be selected and
modified.
A more recent approach integrating geospatial and security standards to support controlled access to spatial information through geo-Web services has been recently developed [19]. In such an approach, a policy specification language, referred
to as GeoXACML, is defined as a geospatial extension of the OASIS eXtensible
access control markup language (XACML). GeoXACML supports the specification
of rules which enable or deny the access to geospatial objects based on spatial criteria, such as topological relationships. As an example, consider the rule which states
that an operation can be performed only on buildings which are located with the administrative boundary of Washington, DC. This approach has some similarities with
the notion of authorization window, though in the window-based model [5] not only
restrictions over objects can be specified but also on an administration policy.
Access Control in Mobile Applications
None of the previous models is conceived for use in a dynamic environment, which
instead is the main concern of spatial and non-spatial context aware access control
models.
197
Access Control for Geospatial Data
The first access control model for geographical data has been proposed [1] to
control the access to georeferenced Earth images. The purpose of such an approach
is the controlled dissemination of satellite images at different levels of resolution
through a DAC policy. In particular, authorizations state which images users are allowed to access and at which resolution. The system, however, is limited in that it
only deals with satellite images. To overcome these limitations, an ACS has been
recently developed for the protection of vector-based data available on Web [5]. The
underlying model is simple but anticipates some ideas that have been more extensively developed by GEO-RBAC. The central concept in such model is that of spatial
authorization. A spatial authorization is defined by the tuple < u, f t, p, w >, where
u denotes the user, f t the object specified in terms of spatial feature types (such as
building or house), p the operation in the form of Web service to be performed on
spatial objects of the specified type (such as InsertOb ject, to introduce a new spatial
element), and w is the authorization window. The authorization window indicates
the geographical scope of the authorization, that is, the portion of space in which the
authorization applies. Accordingly, one can state, for example, that user u is allowed
to carry out operation p on all objects of type f t located in the authorization window
w. Furthermore, the model supports the specification of administrative functions for
the creation and update of spatial authorizations based on a decentralized administration policy. The notion of authorization window has also been integrated in a
different access control model, which has been developed for regulating the access
to a spatial database [2]. The peculiarity of this approach is that the database is based
on a complex spatial data model, enabling multiple levels of spatial representation
at multiple granularities. The access control model thus enables the specification of
which objects at which granularity and in which portion of space can be selected and
modified.
A more recent approach integrating geospatial and security standards to support controlled access to spatial information through geo-Web services has been recently developed [19]. In such an approach, a policy specification language, referred
to as GeoXACML, is defined as a geospatial extension of the OASIS eXtensible
access control markup language (XACML). GeoXACML supports the specification
of rules which enable or deny the access to geospatial objects based on spatial criteria, such as topological relationships. As an example, consider the rule which states
that an operation can be performed only on buildings which are located with the administrative boundary of Washington, DC. This approach has some similarities with
the notion of authorization window, though in the window-based model [5] not only
restrictions over objects can be specified but also on an administration policy.
Access Control in Mobile Applications
None of the previous models is conceived for use in a dynamic environment, which
instead is the main concern of spatial and non-spatial context aware access control
models.
