首页> 外文会议>IFIP WG 11.11 international conference on trust management >Sensor Enhanced Access Control: Extending Traditional Access Control Models with Context-Awareness
【24h】

Sensor Enhanced Access Control: Extending Traditional Access Control Models with Context-Awareness

机译:传感器增强的访问控制:通过上下文感知扩展传统的访问控制模型

获取原文

摘要

Access control models generally distinguish between physical access control that mediates access to physical resources such as buildings, sections of buildings or individual rooms, and logical access control that mediates access to logical objects such as information stored in files or databases. All logical access control models make some, more or less implicit, assumptions about the physical access control model, e.g. that servers are locked in a room with restricted access. However, problems arise when a logical object gets a physical representation, e.g. when a file is displayed on a screen or printed, because the logical access control model has no way to ensure, or even to monitor, that the physical access control policies are being enforced. Traditionally, physical access control policies are enforced by compartmen-talization. Users are separated from other users and resources by placing them in different physical locations such as different offices in a building. Access from one to the other is impossible without passing a guard or a door lock, i.e., guards or distribution of keys/access-cards effectively enforce the physical access control policy. However, these mechanisms are generally coarse-grained, inflexible and expensive. In this paper, we propose a Sensor Enhanced Access Control (SEAC) model that extends existing logical access control models with context-awareness. This allows the model to incorporate information about the physical environment and to explicitly define and enforce physical access control policies for logical objects that have physical representations. A prototype implementation of the SEAC model has been developed for the Unix platform. The prototype protects file data when displayed on a computer screen by managing the visibility of windows in the X Window System. Context-awareness is provided by a simple motion detection system build using cheap web-cameras. However, the system is designed so that the sensor component easily can be replaced, making it possible to deploy advanced sensor technologies.
机译:访问控制模型通常区分介导对诸如建筑物,建筑物的部分或单个房间的物理资源的访问的物理访问控制和介导对诸如存储在文件或数据库中的信息的逻辑对象的访问的逻辑访问控制。所有逻辑访问控制模型都对物理访问控制模型进行了或多或少的隐式假设。将服务器锁定在访问受限的房间中。但是,当逻辑对象获得物理表示时,例如当对象出现问题时,就会出现问题。当文件显示在屏幕上或在屏幕上打印时,因为逻辑访问控制模型无法确保甚至监视物理访问控制策略是否正在执行。传统上,物理访问控制策略是通过隔离来强制执行的。通过将用户放置在不同的物理位置(例如建筑物中的不同办公室),将用户与其他用户和资源分开。如果没有通过门卫或门锁,即从门卫或钥匙/门禁卡的分发有效地执行了物理访问控制策略,则不可能进行从另一个到另一门的访问。然而,这些机制通常是粗粒度的,不灵活的且昂贵的。在本文中,我们提出了一种传感器增强型访问控制(SEAC)模型,该模型通过上下文感知扩展了现有的逻辑访问控制模型。这允许模型合并有关物理环境的信息,并为具有物理表示形式的逻辑对象明确定义和实施物理访问控制策略。 SEAC模型的原型实现已为Unix平台开发。该原型通过管理X窗口系统中窗口的可见性来保护文件数据在计算机屏幕上的显示。通过使用廉价的网络摄像机构建的简单运动检测系统即可提供上下文感知。但是,该系统经过精心设计,可以轻松更换传感器组件,从而有可能部署先进的传感器技术。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号