202
Maria Luisa Damiani and Elisa Bertino
9.4.3 Specification of Core GEO-RBAC
Now, we present the above concepts in more formal terms. Core GEO-RBAC is
presented as organized in a number of logical parts, one for each major set of the
RBAC model, that is roles, permissions, users, and sessions.
The general structure of the model is illustrated in Fig. 9.1.
We use the graphical representation adopted for RBAC. In defining the model, we
refer to the notation introduced in the previous section and summarized in Table 9.1.
Preliminarily, we introduce the notion of partial ordering of features and feature
types. Let FT be the set of feature types and f t i , f t j ∈ FT , with i j, be two
elements of the set. We say that f t i is contained in f t j , denoted by f t i ⊆ f t f t j , if
for each feature f i of type f t i , a feature f j of type f t j exists such that the geometry
of f i is contained in the geometry of f j . For example, the relation of containment
between Town and Region is written as T own ⊆ f t Region. Similarly, we say that the
feature f i is contained in feature f j , denoted by f i ⊆ f f j , when the geometry of f i is
contained in the geometry of f j . As we will see, such relationships will be useful in
characterizing the relationships between locations and roles.
PRMS
OPS
OBJ
R I
R S
S P A
S
S P A I
U
RPOS
SES
S U A
Session-Roles
S e s s io n U s e r s
EnabledSessionRoles
SPATIAL
ROLES
Fig. 9.1. Core GEO-RBAC
Table 9.1. Notation for the main sets used in GEO-RBAC
Notation
Meaning
FT
Feature types
F
Features
R
Role names
S ES
Sessions
U
Users
REXT FT
Role extent types
LPOS FT
Logical positions types
LPOS
Logical positions
RPOS
Real positions
M
Position mapping functions
OPS
Operations
OBJ
Objects
Maria Luisa Damiani and Elisa Bertino
9.4.3 Specification of Core GEO-RBAC
Now, we present the above concepts in more formal terms. Core GEO-RBAC is
presented as organized in a number of logical parts, one for each major set of the
RBAC model, that is roles, permissions, users, and sessions.
The general structure of the model is illustrated in Fig. 9.1.
We use the graphical representation adopted for RBAC. In defining the model, we
refer to the notation introduced in the previous section and summarized in Table 9.1.
Preliminarily, we introduce the notion of partial ordering of features and feature
types. Let FT be the set of feature types and f t i , f t j ∈ FT , with i j, be two
elements of the set. We say that f t i is contained in f t j , denoted by f t i ⊆ f t f t j , if
for each feature f i of type f t i , a feature f j of type f t j exists such that the geometry
of f i is contained in the geometry of f j . For example, the relation of containment
between Town and Region is written as T own ⊆ f t Region. Similarly, we say that the
feature f i is contained in feature f j , denoted by f i ⊆ f f j , when the geometry of f i is
contained in the geometry of f j . As we will see, such relationships will be useful in
characterizing the relationships between locations and roles.
PRMS
OPS
OBJ
R I
R S
S P A
S
S P A I
U
RPOS
SES
S U A
Session-Roles
S e s s io n U s e r s
EnabledSessionRoles
SPATIAL
ROLES
Fig. 9.1. Core GEO-RBAC
Table 9.1. Notation for the main sets used in GEO-RBAC
Notation
Meaning
FT
Feature types
F
Features
R
Role names
S ES
Sessions
U
Users
REXT FT
Role extent types
LPOS FT
Logical positions types
LPOS
Logical positions
RPOS
Real positions
M
Position mapping functions
OPS
Operations
OBJ
Objects
