首页> 外文会议>IFIP WG 11.11 international conference on trust management >Sensor Enhanced Access Control: Extending Traditional Access Control Models with Context-Awareness
【24h】

Sensor Enhanced Access Control: Extending Traditional Access Control Models with Context-Awareness

机译:传感器增强的访问控制:扩展了传统的访问控制模型,具有上下文意识

获取原文

摘要

Access control models generally distinguish between physical access control that mediates access to physical resources such as buildings, sections of buildings or individual rooms, and logical access control that mediates access to logical objects such as information stored in files or databases. All logical access control models make some, more or less implicit, assumptions about the physical access control model, e.g. that servers are locked in a room with restricted access. However, problems arise when a logical object gets a physical representation, e.g. when a file is displayed on a screen or printed, because the logical access control model has no way to ensure, or even to monitor, that the physical access control policies are being enforced. Traditionally, physical access control policies are enforced by compartmen-talization. Users are separated from other users and resources by placing them in different physical locations such as different offices in a building. Access from one to the other is impossible without passing a guard or a door lock, i.e., guards or distribution of keys/access-cards effectively enforce the physical access control policy. However, these mechanisms are generally coarse-grained, inflexible and expensive. In this paper, we propose a Sensor Enhanced Access Control (SEAC) model that extends existing logical access control models with context-awareness. This allows the model to incorporate information about the physical environment and to explicitly define and enforce physical access control policies for logical objects that have physical representations. A prototype implementation of the SEAC model has been developed for the Unix platform. The prototype protects file data when displayed on a computer screen by managing the visibility of windows in the X Window System. Context-awareness is provided by a simple motion detection system build using cheap web-cameras. However, the system is designed so that the sensor component easily can be replaced, making it possible to deploy advanced sensor technologies.
机译:访问控制模型通常区分了解对物理资源的物理访问控制,例如建筑物,建筑物或单个房间的部分,以及调解对存储在文件或数据库中的信息的逻辑对象的访问权限的逻辑访问控制。所有逻辑访问控制模型都在物理访问控制模型中制作一些,或多或少隐含的假设,例如,该服务器被锁在具有受限制的房间。但是,当逻辑对象获得物理表示时出现问题,例如,当文件显示在屏幕上或打印文件时,因为逻辑访问控制模型无法确保或甚至监视,因此正在强制执行物理访问控制策略。传统上,Compartmen-Talization强制执行物理访问控制策略。用户将其与其他用户和资源分开,将它们放在建筑物中的不同办公室等不同的物理位置在不通过后卫或门锁的情况下,不可能从一个到另一个,即钥匙/接入卡的防护或分发,有效地强制执行物理访问控制策略。然而,这些机制通常是粗粒,不灵活和昂贵的。在本文中,我们提出了一种传感器增强的访问控制(SEAC)模型,其扩展了具有上下文意识的现有逻辑访问控制模型。这允许模型包含有关物理环境的信息,并明确定义和强制执行具有物理表示的逻辑对象的物理访问控制策略。已经为UNIX平台开发了SEAC模型的原型实现。通过管理X Window系统中的Windows的可见性在计算机屏幕上显示时,原型保护文件数据。使用廉价的Web-Cameras构建简单的运动检测系统提供了上下文意识。但是,系统设计成使传感器组件容易替换,可以部署高级传感器技术。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号