9 Access Control Systems for Geospatial Data and Applications
203
Role Schema and Instance
A role schema defines a common name for a set of roles, the role extent type, the logical position type, and the position mapping functions relating the real position with
the logical position. A role instance is defined over an extent of the type specified in
the corresponding schema, while the logical position of the individual playing such
a role is determined by the position mapping function specified in the schema alike.
The formal definitions of role schema and instance are reported below [4]:
Definition 9.2 (Role Schema). A Role Schema is a tuple < r, ext, loc, m loc > where:
• r ∈ R;
• ext ∈ REXT FT ;
• loc ∈ LPOS FT ;
• loc ⊆ f t ext;
• m loc ∈ M is a location mapping function for feature type loc.
We denote with R S the set of role schemas and we assume that, given a role name
r ∈ R, r is unique in R S . A role schema is also denoted as r(ext, loc, m loc ).
Definition 9.3 (Role Instance). Given a role schema r s ∈ R S , an instance r i of r s is
a pair < r, e > where r is the name of the role in schema r s , thus r = r s .r and e ∈ F
is a feature of type r s .ext. The schema of r i is denoted by S chemaO f (r i ). We denote
with R I the set of role instances for all role schemas. A role instance is also denoted
as r(e).
Permission
A permission is associated with each service. In our model, permissions can be associated either with the role schema and inherited by all role instances of the schema or
directly with the role instances. Such different granularities are formalized by introducing two functions: S PrmsAssignment, relating roles schemas and permissions
sets; I PrmsAssignment relating spatial roles, thus role instances, to specific permissions. Function I PrmsAssignment
∗ is then introduced to combine permissions
directly assigned to spatial roles with permissions inherited from their role schema.
Formally [4]:
Definition 9.4 (Permissions). The set of permissions PRMS is defined as PRMS =
2
(OPS ×OBJ) . We also define:
• S PA S : R S ×PRMS , a many-to-many mapping permission-to-spatial role schema
assignment relation;
• S PrmsAssignment : R S → 2
PRMS , the mapping of spatial role schema onto
a set of permissions. Given a role schema r s , S PrmsAssignment(r s ) = {p ∈
PRMS | < r s , p >∈ S PA S };
• S PA I : R I ×PRMS , a many-to-many mapping permission-to-spatial role instance
assignment relation;
203
Role Schema and Instance
A role schema defines a common name for a set of roles, the role extent type, the logical position type, and the position mapping functions relating the real position with
the logical position. A role instance is defined over an extent of the type specified in
the corresponding schema, while the logical position of the individual playing such
a role is determined by the position mapping function specified in the schema alike.
The formal definitions of role schema and instance are reported below [4]:
Definition 9.2 (Role Schema). A Role Schema is a tuple < r, ext, loc, m loc > where:
• r ∈ R;
• ext ∈ REXT FT ;
• loc ∈ LPOS FT ;
• loc ⊆ f t ext;
• m loc ∈ M is a location mapping function for feature type loc.
We denote with R S the set of role schemas and we assume that, given a role name
r ∈ R, r is unique in R S . A role schema is also denoted as r(ext, loc, m loc ).
Definition 9.3 (Role Instance). Given a role schema r s ∈ R S , an instance r i of r s is
a pair < r, e > where r is the name of the role in schema r s , thus r = r s .r and e ∈ F
is a feature of type r s .ext. The schema of r i is denoted by S chemaO f (r i ). We denote
with R I the set of role instances for all role schemas. A role instance is also denoted
as r(e).
Permission
A permission is associated with each service. In our model, permissions can be associated either with the role schema and inherited by all role instances of the schema or
directly with the role instances. Such different granularities are formalized by introducing two functions: S PrmsAssignment, relating roles schemas and permissions
sets; I PrmsAssignment relating spatial roles, thus role instances, to specific permissions. Function I PrmsAssignment
∗ is then introduced to combine permissions
directly assigned to spatial roles with permissions inherited from their role schema.
Formally [4]:
Definition 9.4 (Permissions). The set of permissions PRMS is defined as PRMS =
2
(OPS ×OBJ) . We also define:
• S PA S : R S ×PRMS , a many-to-many mapping permission-to-spatial role schema
assignment relation;
• S PrmsAssignment : R S → 2
PRMS , the mapping of spatial role schema onto
a set of permissions. Given a role schema r s , S PrmsAssignment(r s ) = {p ∈
PRMS | < r s , p >∈ S PA S };
• S PA I : R I ×PRMS , a many-to-many mapping permission-to-spatial role instance
assignment relation;
