Presentation is loading. Please wait.

Presentation is loading. Please wait.

17 July 2006IWUAC 2006, San Jose, California Using semantic policies for ad-hoc coalition access control Anand Dersingh 1, Ramiro Liscano 2, and Allan.

Similar presentations


Presentation on theme: "17 July 2006IWUAC 2006, San Jose, California Using semantic policies for ad-hoc coalition access control Anand Dersingh 1, Ramiro Liscano 2, and Allan."— Presentation transcript:

1 17 July 2006IWUAC 2006, San Jose, California Using semantic policies for ad-hoc coalition access control Anand Dersingh 1, Ramiro Liscano 2, and Allan Jost 1 1 Faculty of Computer Science, Dalhousie University, Halifax, NS, Canada 2 Faculty of Engineering and Applied Sciences, University of Ontario Institute of Technology, Oshawa, ON, Canada

2 IWUAC 2006, San Jose, California 17 July 2006 Outline Introduction Background Proposed Approach System Architecture Implementation Results Summary

3 IWUAC 2006, San Jose, California 17 July 2006 Introduction Collaborative Environments  Inter-organizational collaboration  Ad-hoc collaborations Access Control  Role-Based Access Control  Coalition-Based Access Control

4 IWUAC 2006, San Jose, California 17 July 2006 Ad-hoc Coalition A user in site A may want to share his personal services to the outsiders under the condition that they are participating in a SIP call with the user in site A. The problems arise due to the fact that a firewall may block the outside access to the service

5 IWUAC 2006, San Jose, California 17 July 2006 Ad-hoc Coalition Rudimentary solution  Leave ports open Security concerns  Manually open and close ports Requires advance users Error prone

6 IWUAC 2006, San Jose, California 17 July 2006 Ad-hoc Coalition Spontaneous access rights  Specified by users  Short term agreements (temporary)  Context dependant

7 IWUAC 2006, San Jose, California 17 July 2006 Why Semantic Web? Context must be represented in a formal way  Ontologies Concepts  relationships and properties  Machine processable

8 IWUAC 2006, San Jose, California 17 July 2006 Why PBNM? Automation process  Configuring devices can be invisible from user point of view Managing network as a whole

9 IWUAC 2006, San Jose, California 17 July 2006 Proposed Approach Context-Aware Access Control  Knowledge Modeling and Representation Users Devices Services  WSDL RDF Mapping  Context-Based Access Control Policy Integration of context into access control policy

10 IWUAC 2006, San Jose, California 17 July 2006 System Architecture

11 IWUAC 2006, San Jose, California 17 July 2006 Implementation Focusing on domain knowledge representation and context-based access control policy Tools  Rein  CWM  N3, RDF, OWL  WSDL RDF Mapping

12 IWUAC 2006, San Jose, California 17 July 2006 Context Acquisition Acquires and monitors events in the real world Uses rules and reasoning capability in order to acquire knowledge from the real world At least one KH on each domain

13 IWUAC 2006, San Jose, California 17 July 2006 Partial Representation

14 IWUAC 2006, San Jose, California 17 July 2006 WSDL RDF Mapping :projectService a rwsdl:Service ; rwsdl:endpoint projectEndpoint. projectEndpoint a rwsdl:Endpoint ; rwsdl:address.

15 IWUAC 2006, San Jose, California 17 July 2006 Policy {?OWNER a ont:Person. ?SIPCALL a ont:SIPCall. ?OWNER ont:incall ?SIPCALL. ?OWNER ont:owns ?DEVICE. ?DEVICE a ont:Device. ?SERVICE ont:target ?DEVICE. ?WHO a ont:Person. ?WHO ont:incall ?SIPCALL. } => {?WHO reina:ispermitted ?SERVICE}.

16 IWUAC 2006, San Jose, California 17 July 2006 Results Knowledge representation  Context  Services  Entities Context-aware access control policy  Spontaneous access rights

17 IWUAC 2006, San Jose, California 17 July 2006 Summary Controlling access in dynamic environments  Ad-hoc coalition Other context information Policy translation  Policy to device configurations


Download ppt "17 July 2006IWUAC 2006, San Jose, California Using semantic policies for ad-hoc coalition access control Anand Dersingh 1, Ramiro Liscano 2, and Allan."

Similar presentations


Ads by Google