204
Maria Luisa Damiani and Elisa Bertino
• I PrmsAssignment : R I → 2
PRMS the mapping of spatial role instance onto
a set of permissions. Given a role instance r i , I PrmsAssignment(r i ) = {p ∈
PRMS | < r i , p >∈ S PA I };
• I PrmsAssignment
∗ : R I → 2
PRMS such that given a role instance r i ,
I PrmsAssignment
∗ (r i ) = I PrmsAssignment(r i ) ∪ S PrmsAssignment(S chemaO f (r i ))}. Hence, the permissions of a role are those assigned to its schema
plus those directly assigned to the instance.
Users and Session
Spatial roles are assigned to users. The definition of the model for this part is conceptually analogous to that in RBAC. In particular, given a set of users, the following
relations are defined: the many-to-many relation S UA relates users and role instances; the function S R AssignedU ser maps a role instance onto the set of users
which can activate that role. Formally [4]:
Definition 9.5 (Users). We define:
• S UA ⊆ U × R I , a mapping user-to-spatial role instance assignment relation;
• S R AssignedU ser : R I → 2
U , the mapping of spatial role instance onto a set
of users. Formally, S R AssignedU ser(< r, e >∈ R I ) = {u ∈ U|(u, < r, e >)
∈ S UA}.
When a user logs in, a new session is activated and a number of roles are
selected to be included in the session role set. Given a session s, the following two functions are defined: S essionU ser(s) corresponds to the user of the session; S essionRoles(s) corresponds to the role that can be potentially activated in s.
Formally [4]:
Definition 9.6 (Sessions). We define:
• S essionU ser: S ES → U, the mapping from a session s to the user of s;
• S essionRoles: S ES → 2
R I with S essionRoles(s) ⊆ {< r, e >∈ R I |(S essionU ser(s), < r, e >) ∈ S UA}.
Access Control Mechanism
The session roles are the roles that the user of the session has selected. However, for
a session role to be enabled, the user should be logically located within the space
of the corresponding role extent. Therefore, depending on the user position during
that session, only a subset of the session roles is enabled and permissions granted. In
order to compute the logical position of a user playing a role r in a session, the location mapping function defined in the schema of r is applied to the user real position,
provided by the external environment. Hence, if the logical position of the user is spatially contained in the extent of r, the role is enabled and thus the set of permissions
assigned to the corresponding role is determined. Given a user’s request, the access
Précédent

- 197/317

Suivant