1st International ICST Conference on Security and Privacy for Emerging Areas in Communication Networks

Research Article

Short Paper: Towards a Location-Aware Role-Based Access Control Model

  • @INPROCEEDINGS{10.1109/SECURECOMM.2005.50,
        author={I.  Ray and Lijun  Yu },
        title={Short Paper: Towards a Location-Aware Role-Based Access Control Model},
        proceedings={1st International ICST Conference on Security and Privacy for Emerging Areas in Communication Networks},
        publisher={IEEE},
        proceedings_a={SECURECOMM},
        year={2006},
        month={3},
        keywords={},
        doi={10.1109/SECURECOMM.2005.50}
    }
    
  • I. Ray
    Lijun Yu
    Year: 2006
    Short Paper: Towards a Location-Aware Role-Based Access Control Model
    SECURECOMM
    IEEE
    DOI: 10.1109/SECURECOMM.2005.50
I. Ray1, Lijun Yu 1
  • 1: Colorado State University

Abstract

With the growing use of wireless networks and mobile devices, we are moving towards an era where location information will be necessary for access control. The use of location information can be used for enhancing the security of an application, and it can also be exploited to launch attacks. For critical applications, a formal model for location-based access control is needed that increases the security of the application and ensures that the location information cannot be exploited to cause harm. In this paper, we show how the Role-Based Access Control (RBAC) model can be extended to incorporate the notion of location. We show how the different components in the RBAC model are related with location and how this location information can be used to determine whether a subject has access to a given object. This model is suitable for applications consisting of static and dynamic objects, where location of the subject and object must be considered before granting access.