212
Maria Luisa Damiani and Elisa Bertino
Concluding Remarks
It may have been noticed that in discussing the two architectural approaches, the
centralized and the distributed one, we have focused on different aspects. In the centralized solution, the major concern is for the strategy to apply for the enforcement of
the security policy which can be user-driven or event-driven. In the decentralized solution, the focus is on distributing the administrative and enforcement functionalities.
The question which has not been addressed yet is whether in the decentralized context the enforcement strategy is user-driven or event-driven. This problem deserves
a careful analysis, especially if we want to account for services that are not only of
pull but also of push type. This issue will be addressed as part of our future work.
9.6 Conclusions
In this chapter, we have discussed issues related to access control in location-based
applications. Such applications are characterized by a large variety of requirements
affecting both the conceptual definition of access control models and the architectures of ACS. In this chapter, we have shown a rich model, GEO-RBAC, specifically
tailored to geospatial applications with mobile users and then illustrated possible
architectures supporting such model.
Several issues, however, are still to be addressed concerning the architectural
aspects. In particular, the integration of the privacy dimension into access control,
following the guidelines proposed in [11], is an important issue, given the existing
privacy regulations and the increased privacy concerns by citizens and organizations.
The mapping of GEO-RBAC onto an existing architectural framework, X-GTRBAC,
is also crucial to obtain an ACS supporting the specification and enforcement of a
rich set of context-based access control policies.
Acknowledgments
The work of M.L. Damiani has been partially supported by the European project
GEOPKDD “Geographic Privacy-aware Knowledge Discovery and Delivery.” The
work of E. Bertino has been supported by USA NSF under the project “A Comprehensive Policy-Driven Framework for Online Privacy Protection: Integrating IT,
Human, Legal and Economic Perspectives” and by the sponsors of CERIAS.
References
1. Atluri V, Mazzoleni P (2002) A Uniform Indexing Scheme for Geospatial Data and Authorizations. In: Proc. 6th Conf., on Data and Application Security, IFIP TC11/WG11.3,
Cambridge, UK, 207–218
Maria Luisa Damiani and Elisa Bertino
Concluding Remarks
It may have been noticed that in discussing the two architectural approaches, the
centralized and the distributed one, we have focused on different aspects. In the centralized solution, the major concern is for the strategy to apply for the enforcement of
the security policy which can be user-driven or event-driven. In the decentralized solution, the focus is on distributing the administrative and enforcement functionalities.
The question which has not been addressed yet is whether in the decentralized context the enforcement strategy is user-driven or event-driven. This problem deserves
a careful analysis, especially if we want to account for services that are not only of
pull but also of push type. This issue will be addressed as part of our future work.
9.6 Conclusions
In this chapter, we have discussed issues related to access control in location-based
applications. Such applications are characterized by a large variety of requirements
affecting both the conceptual definition of access control models and the architectures of ACS. In this chapter, we have shown a rich model, GEO-RBAC, specifically
tailored to geospatial applications with mobile users and then illustrated possible
architectures supporting such model.
Several issues, however, are still to be addressed concerning the architectural
aspects. In particular, the integration of the privacy dimension into access control,
following the guidelines proposed in [11], is an important issue, given the existing
privacy regulations and the increased privacy concerns by citizens and organizations.
The mapping of GEO-RBAC onto an existing architectural framework, X-GTRBAC,
is also crucial to obtain an ACS supporting the specification and enforcement of a
rich set of context-based access control policies.
Acknowledgments
The work of M.L. Damiani has been partially supported by the European project
GEOPKDD “Geographic Privacy-aware Knowledge Discovery and Delivery.” The
work of E. Bertino has been supported by USA NSF under the project “A Comprehensive Policy-Driven Framework for Online Privacy Protection: Integrating IT,
Human, Legal and Economic Perspectives” and by the sponsors of CERIAS.
References
1. Atluri V, Mazzoleni P (2002) A Uniform Indexing Scheme for Geospatial Data and Authorizations. In: Proc. 6th Conf., on Data and Application Security, IFIP TC11/WG11.3,
Cambridge, UK, 207–218
