Title
A general obligation model and continuity: enhanced policy enforcement engine for usage control
Abstract
The usage control model (UCON) has been proposed to augment traditional access control models by integrating authorizations, obligations, and conditions and providing the properties of decision continuity and attribute mutability. Several recent work have applied UCON to support security requirements in different computing environments such as resource sharing in collaborative computing systems and data control in remote platforms. In this paper we identify two individual but interrelated problems of the original UCON model and recent implementations: oversimplifying the concept of usage session of the model, and the lack of comprehensive ongoing enforcement mechanism of implementations. We extend the core UCON model with continuous usage sessions thus extensively augment the expressiveness of obligations in UCON, and then propose a general, continuity-enhanced and configurable usage control enforcement engine. Finally we explain how our approach can satisfy flexible security requirements with an implemented prototype for a healthcare information system.
Year
DOI
Venue
2008
10.1145/1377836.1377856
SACMAT
Keywords
Field
DocType
comprehensive ongoing enforcement mechanism,data control,collaborative computing system,usage control model,traditional access control model,continuous usage session,original ucon model,general obligation model,enhanced policy enforcement engine,usage session,configurable usage control enforcement,core ucon model,security,design,resource sharing,context based access control,satisfiability,pervasive computing,rbac
Information system,Computer science,Computer security,Role-based access control,Implementation,Context-based access control,Access control,Enforcement,Ubiquitous computing,Shared resource
Conference
Citations 
PageRank 
References 
36
1.53
23
Authors
5
Name
Order
Citations
PageRank
Basel Katt17711.48
Zhang Xinwen21695104.61
Ruth Breu384389.52
Michael Hafner414511.46
Jean-Pierre Seifert51946160.31