9 Access Control Systems for Geospatial Data and Applications
211
be viable, however, clients must be aware of the position of users and then be able
to match such position against role extents. Clients can obtain the position from the
Location Server or from the positioning device eventually installed on terminal. In
any case, since clients may be not trusted, it is important to ensure the integrity of
position data. To that purpose, we assume position data to be provided along with a
digital signature by a Secure Location Server.
Access control operations on clients are then carried out by a software component
called local access control (LAC). Based on role certificates and user’s position, the
LAC determines the roles, which are enabled, and then, if there is at least an enabled
role, it transmits to the application server an encrypted access request that includes
the role certificate and the position. Note that the application server trusts the position
sent by the client because the position has a digital signature affixed. Therefore, a
malicious client cannot forge such information.
Now we consider what happens on the server side when a request is sent by
LAC. The request is received by one of the ACS defined in the framework, say
ACS j . Based on the role certificate and position data sent by the client, ACS j verifies
whether the role is enabled. Notice that this operation is performed twice, first at the
client and then at the server side. The reason is that the client may not be trusted,
and thus, the server needs to make sure that constraints are fulfilled, with the advantage that in the case of trusted clients, unnecessary request processing at the server
is avoided. Finally, the system checks whether the requested service is one of the
services, which have been assigned to the specified role based on the local security
policy. If this is the case, the access is permitted.
The decentralized architecture comprehensive of the LAC layer, the Role Provider,
the Secure Location Server, and the set {ACS 1 , .., ACS n } of ACS is shown in Fig. 9.4.
Fig. 9.4. Decentralized architecture
211
be viable, however, clients must be aware of the position of users and then be able
to match such position against role extents. Clients can obtain the position from the
Location Server or from the positioning device eventually installed on terminal. In
any case, since clients may be not trusted, it is important to ensure the integrity of
position data. To that purpose, we assume position data to be provided along with a
digital signature by a Secure Location Server.
Access control operations on clients are then carried out by a software component
called local access control (LAC). Based on role certificates and user’s position, the
LAC determines the roles, which are enabled, and then, if there is at least an enabled
role, it transmits to the application server an encrypted access request that includes
the role certificate and the position. Note that the application server trusts the position
sent by the client because the position has a digital signature affixed. Therefore, a
malicious client cannot forge such information.
Now we consider what happens on the server side when a request is sent by
LAC. The request is received by one of the ACS defined in the framework, say
ACS j . Based on the role certificate and position data sent by the client, ACS j verifies
whether the role is enabled. Notice that this operation is performed twice, first at the
client and then at the server side. The reason is that the client may not be trusted,
and thus, the server needs to make sure that constraints are fulfilled, with the advantage that in the case of trusted clients, unnecessary request processing at the server
is avoided. Finally, the system checks whether the requested service is one of the
services, which have been assigned to the specified role based on the local security
policy. If this is the case, the access is permitted.
The decentralized architecture comprehensive of the LAC layer, the Role Provider,
the Secure Location Server, and the set {ACS 1 , .., ACS n } of ACS is shown in Fig. 9.4.
Fig. 9.4. Decentralized architecture
