Access Control Metamodel for Policy Specification and Enforcement: From Conception to Formalization

被引:3
|
作者
Kashmar, Nadine [1 ,3 ]
Adda, Mehdi [1 ]
Atieh, Mirna [2 ]
Ibrahim, Hussein [3 ]
机构
[1] Univ Quebec Rimouski, Dept Math Informat & Genie, 300 Allee Ursulines, Rimouski, PQ G5L 3A1, Canada
[2] Lebanese Univ, Fac Econ Sci & Adm, Business Comp Dept, Hadat, Lebanon
[3] Inst Technol Maintenance Ind, 175 Rue Verendrye, Sept Iles, PQ G4R 5B7, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
access control; metamodel; security and privacy; IoT; policy;
D O I
10.1016/j.procs.2021.03.111
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the widespread of data, applications, and devices in today's dynamic computing environments, controlling access to assets from multiple sources is a key challenge, especially with the presence of cybercriminals and cyberattacks. Several access control (AC) models are developed and implemented in different computing environments to control users' access to resources. But, the emergence of ubiquitous computing, especially the concept of industry 4.0 and IoT applications, releases new prospects to traditional information systems by merging new technologies and services for seamless access to information sources at anytime and anywhere. With this fact, it is realized that these AC models no longer meet the increasing demand for privacy and security standards. Hence, several AC metamodels with higher level of abstraction are developed as unifying frameworks for specifying any AC policy. Unfortunately, the proposed AC metamodels have several limitations. One of these limitations is that they are not generic enough to include all features and the heterogeneous AC models. In this paper we propose a solution for this limitation by developing a generic AC metamodel where its features can be upgraded to answer the needs and facts of the new technologies. (C) 2021 The Authors. Published by Elsevier B.V.
引用
收藏
页码:887 / 892
页数:6
相关论文
共 50 条
  • [1] Access Control Policy Specification Language Based on Metamodel
    Luo Y.
    Shen Q.-N.
    Wu Z.-H.
    [J]. Ruan Jian Xue Bao/Journal of Software, 2020, 31 (02): : 439 - 454
  • [2] A Metamodel for the Design of Access-Control Policy Enforcement Managers: Work in Progress
    Jiague, Michel Embe
    Frappier, Marc
    Gervais, Frederic
    Laleau, Regine
    St-Denis, Richard
    [J]. FOUNDATIONS AND PRACTICE OF SECURITY, 2011, 6888 : 218 - +
  • [3] The Policy Machine: A novel architecture and framework for access control policy specification and enforcement
    Ferraiolo, David
    Atluri, Vijayalakshmi
    Gavrila, Serban
    [J]. JOURNAL OF SYSTEMS ARCHITECTURE, 2011, 57 (04) : 412 - 424
  • [4] DC Proposal: Knowledge Based Access Control Policy Specification and Enforcement
    Kirrane, Sabrina
    [J]. SEMANTIC WEB - ISWC 2011, PT II, 2011, 7032 : 293 - 300
  • [5] Specification & Enforcement of Access Control in Information & Communication Systems
    El Kalam, Anas Abou
    [J]. 2008 3RD INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGIES: FROM THEORY TO APPLICATIONS, VOLS 1-5, 2008, : 2580 - 2585
  • [6] Specification and enforcement of access control in heterogeneous distributed applications
    Fink, T
    Koch, M
    Oancea, C
    [J]. WEB SERVICES -ICWS-EUROPE 2003, PROCEEDINGS, 2003, 2853 : 88 - 100
  • [7] A Rigorous Framework for Specification, Analysis and Enforcement of Access Control Policies
    Margheri, Andrea
    Masi, Massimiliano
    Pugliese, Rosario
    Tiezzi, Francesco
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2019, 45 (01) : 2 - 33
  • [8] Checking Policy Enforcement in an Access Control Aspect Model
    Song, Eunjee
    France, Robert
    Ray, Indrakshi
    Kim, Hanil
    [J]. INFORMATION-AN INTERNATIONAL INTERDISCIPLINARY JOURNAL, 2008, 11 (05): : 541 - 552
  • [9] Access Control for Database Applications: Beyond Policy Enforcement
    Zhang, Wen
    Panda, Aurojit
    Shenker, Scott
    [J]. PROCEEDINGS OF THE 19TH WORKSHOP ON HOT TOPICS IN OPERATING SYSTEMS, HOTOS 2023, 2023, : 223 - 230
  • [10] Using RDF for policy specification and enforcement
    Carminati, B
    Ferrari, E
    Thuraisingham, B
    [J]. 15TH INTERNATIONAL WORKSHOP ON DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2004, : 163 - 167