198
Maria Luisa Damiani and Elisa Bertino
Non-spatial context-aware access control models include generalized TRBAC
(GTRBAC) [18], a RBAC-based model which incorporates a set of language
constructs for the specification of various temporal constraints on roles, including
constraints on role enabling, role activation, user-to-role assignments, and
permission-to-role assignments. X-GTRBAC [7] is another approach which augments GTRBAC with XML for supporting the policy enforcement in a heterogeneous, distributed environment. In addition to temporal constraints, the model
also supports non-temporal contextual constraints. The approach, however, is more
focused on the software engineering aspects of the access control rather than on
the expressivity of the policy specification language. A notable approach is the one
proposed through the Generalized RBAC (GRBAC) [10]. GRBAC introduces the
concept of environment roles; that is, roles that can be activated based on the value
of conditions in the environment where the request has been made. Environmental
conditions include time, location, and other contextual information that is relevant to
access control. If compared with GEO-RBAC, the concepts of role extent and user
position are close to that of context variables. However, the mechanism of contexts
is very general and does not account for the specificity of spatial information, such
as the multi-granularity of position and the spatial relationships that may exist between the spatial elements in space. Moreover, in GEO-RBAC a common spatial data
model is adopted in order to provide a uniform and standard-based representation of
locational aspects that, notably, involve not only roles but also protected objects.
The spatial dimension of access control is the basic component of the approach
presented in [15]. In such work, an extension of the RBAC model is proposed based
on the notion of spatial role, intended as a role that is automatically activated when
the user is in a given position. The space model is however very simple and targeted
to wireless network applications. It consists of a set of adjacent cells and the position
of the user is the cell or the aggregate of cells containing it. The spatial granularity of
the position is thus fixed while the space is rigidly structured and the position itself
does not have any semantic meaning but simply a geometric value. By contrast, in
GEO-RBAC the granularity of the user position may depend on the role of the user;
thus no assumption is made on the space layout. Moreover, in GEO-RBAC the spatial
dimension integrates geometric and semantic knowledge about the world.
A different approach which combines space and time is presented in [9]; this
approach borrows from GEO-RBAC the distinction between real position and logical
position and from GTRBAC the notion of temporal context. Such a model, however,
does not include the notion of schema, neither supports important features of GEORBAC such as hierarchies of enabled roles and spatially aware SoD constraints.
9.4 An Access Control Model for Location-aware Applications:
GEO-RBAC
GEO-RBAC is a comprehensive access control model specifically developed to
address access control requirements of applications characterized by users that are
members of mobile organizations. By mobile organization, we mean a community of
Maria Luisa Damiani and Elisa Bertino
Non-spatial context-aware access control models include generalized TRBAC
(GTRBAC) [18], a RBAC-based model which incorporates a set of language
constructs for the specification of various temporal constraints on roles, including
constraints on role enabling, role activation, user-to-role assignments, and
permission-to-role assignments. X-GTRBAC [7] is another approach which augments GTRBAC with XML for supporting the policy enforcement in a heterogeneous, distributed environment. In addition to temporal constraints, the model
also supports non-temporal contextual constraints. The approach, however, is more
focused on the software engineering aspects of the access control rather than on
the expressivity of the policy specification language. A notable approach is the one
proposed through the Generalized RBAC (GRBAC) [10]. GRBAC introduces the
concept of environment roles; that is, roles that can be activated based on the value
of conditions in the environment where the request has been made. Environmental
conditions include time, location, and other contextual information that is relevant to
access control. If compared with GEO-RBAC, the concepts of role extent and user
position are close to that of context variables. However, the mechanism of contexts
is very general and does not account for the specificity of spatial information, such
as the multi-granularity of position and the spatial relationships that may exist between the spatial elements in space. Moreover, in GEO-RBAC a common spatial data
model is adopted in order to provide a uniform and standard-based representation of
locational aspects that, notably, involve not only roles but also protected objects.
The spatial dimension of access control is the basic component of the approach
presented in [15]. In such work, an extension of the RBAC model is proposed based
on the notion of spatial role, intended as a role that is automatically activated when
the user is in a given position. The space model is however very simple and targeted
to wireless network applications. It consists of a set of adjacent cells and the position
of the user is the cell or the aggregate of cells containing it. The spatial granularity of
the position is thus fixed while the space is rigidly structured and the position itself
does not have any semantic meaning but simply a geometric value. By contrast, in
GEO-RBAC the granularity of the user position may depend on the role of the user;
thus no assumption is made on the space layout. Moreover, in GEO-RBAC the spatial
dimension integrates geometric and semantic knowledge about the world.
A different approach which combines space and time is presented in [9]; this
approach borrows from GEO-RBAC the distinction between real position and logical
position and from GTRBAC the notion of temporal context. Such a model, however,
does not include the notion of schema, neither supports important features of GEORBAC such as hierarchies of enabled roles and spatially aware SoD constraints.
9.4 An Access Control Model for Location-aware Applications:
GEO-RBAC
GEO-RBAC is a comprehensive access control model specifically developed to
address access control requirements of applications characterized by users that are
members of mobile organizations. By mobile organization, we mean a community of
