RelBOSS: A Relationship-Aware Access Control Framework for Software Services [chapter]

A. S. M. Kayes, Jun Han, Alan Colman, Md. Saiful Islam
2014 Lecture Notes in Computer Science  
Context-awareness is an important aspect of the dynamically changing environments and the relationship context information brings new benefits to the access control systems. Existing relationship-aware access control approaches are highly domain-specific and consider the expression of access control policies in terms of the relationship context information. However, these approaches are unable to dynamically capture the granularity levels and strengths of the relevant relationship. To this end,
more » ... in this paper we present a formal Relationship-Aware Access Control (RAAC) model for specifying the relevant relationship context information and the corresponding access control policies. Using the RAAC model, we introduce an ontology-based framework, Relationship-Based access control Ontology for Software Services (RelBOSS). One of the main novelties of the framework is that it dynamically captures the relationship context information (the type/name, granularity levels and strengths of the relevant relationship). Experiments with a software prototype confirm the feasibility of our framework.
doi:10.1007/978-3-662-45563-0_15 fatcat:qbow6nc7n5f2vepwcpqnplvz34