Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Journal articles
  4. Data security in location-aware applications: an approach based on RBAC
 
research article

Data security in location-aware applications: an approach based on RBAC

Damiani, M. L.  
•
Bertino, E.
•
Perlasca, P.
2007
International Journal of Information and Computer Security

Data security in a mobile context is a critical issue. Over the last few years a new category of location-based services, the Enterprise LBS (ELBS), has emerged focusing on the demands of mobility in organisations. These applications pose challenging requirements, including the need of selective access to ELBS based on the position of mobile users and spatially bounded organisational roles. To deal with these requirements a novel access control system, named GEO-RBAC, has been developed. GEO-RBAC extends the NIST RBAC (Role-Based Access Control) standard with the notions of spatial role, role-dependent position, role schema and role instance. Further, roles become enabled/disabled based on the position of the user. In the paper we present GEO-RBAC, a full-fledged RBAC-based model, consisting, like RBAC, of three distinct components: the Core GEO-RBAC, the Hierarchical GEO-RBAC and the Constrained GEO-RBAC. The paper focuses on the innovative aspects that have been introduced in the model to account for the spatial dimension. Further, a rigorous specification of the model (reference model) is presented.

  • Details
  • Metrics
Type
research article
DOI
10.1504/IJICS.2007.012243
Author(s)
Damiani, M. L.  
Bertino, E.
Perlasca, P.
Date Issued

2007

Published in
International Journal of Information and Computer Security
Volume

1

Issue

1/2

Start page

5

End page

38

Subjects

access control

•

data security

•

geographic information systems

•

information and computer security

•

location aware applications

•

mobile systems

•

RBAC

•

role based access control

Editorial or Peer reviewed

REVIEWED

Written at

EPFL

EPFL units
LBD  
Available on Infoscience
March 22, 2007
Use this identifier to reference this record
https://infoscience.epfl.ch/handle/20.500.14299/3966
Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés