A Framework for Composition and Enforcement of Privacy-aware and Context-driven Authorization Mechanism for Complex Systems
Download
Author
A M Samuel, M I Sarfraz, H Haseeb and A Ghafoor
Tech report number
CERIAS TR 2011-09
Entry type
techreport
Abstract
Security and privacy of complex systems is a concern due to proliferation of cyber based technologies. Several researchers have pointed out that for the proper enforcement of privacy rules in a complex system, the privacy requirements should be captured in access control systems. In this paper, we present a framework for composition and enforcement of context-aware rules for such systems. The focus of this paper is the design of a system to allow a user (not a system or security administrator) to compose conflict free access control policies for his or her on-line assets. An additional requirement in this case is that such a policy be context-aware. We also present a methodology for verifying the privacy rules to ensure correctness and logical consistency. The verification process is also used to ensure that sensitive security requirements are not violated when privacy rules are enforced.
Download
Date
2011 – 10 – 19
Key alpha
Samuel
Publication Date
2011-10-19

