A Framework for Situation-Aware Access Control in Federated Data-as-a-Service Systems Based on Query Rewriting

Samson Oni, Zhiyuan Chen, Adina Crainiceanu, K. Joshi, Don Needham
{"title":"A Framework for Situation-Aware Access Control in Federated Data-as-a-Service Systems Based on Query Rewriting","authors":"Samson Oni, Zhiyuan Chen, Adina Crainiceanu, K. Joshi, Don Needham","doi":"10.1109/SCC49832.2020.00008","DOIUrl":null,"url":null,"abstract":"Organizations often need to share mission-dependent data in a secure and flexible way. Examples include contact tracing for a contagious disease such as COVID19, maritime search and rescue operations, or creating a collaborative bid for a contract. In such examples, the ability to access data may need to change dynamically, depending on the situation of a mission (e.g., whether a person tested positive for a disease, a ship is in distress, or a bid offer with given properties needs to be created). We present a novel framework to enable situation-aware access control in a federated Data-as-a-Service architecture by using semantic web technologies. Our framework allows distributed query rewriting and semantic reasoning that automatically adds situation based constraints to ensure that users can only see results that they are allowed to access. We have validated our framework by applying it to two dynamic use cases: maritime search and rescue operations and contact tracing for surveillance of a contagious disease. This paper details our implemented solution and experimental results of the two use cases. Our framework can be adopted by organizations that need to share sensitive data securely during dynamic, limited duration scenarios.","PeriodicalId":274909,"journal":{"name":"2020 IEEE International Conference on Services Computing (SCC)","volume":"48 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-10-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE International Conference on Services Computing (SCC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SCC49832.2020.00008","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Organizations often need to share mission-dependent data in a secure and flexible way. Examples include contact tracing for a contagious disease such as COVID19, maritime search and rescue operations, or creating a collaborative bid for a contract. In such examples, the ability to access data may need to change dynamically, depending on the situation of a mission (e.g., whether a person tested positive for a disease, a ship is in distress, or a bid offer with given properties needs to be created). We present a novel framework to enable situation-aware access control in a federated Data-as-a-Service architecture by using semantic web technologies. Our framework allows distributed query rewriting and semantic reasoning that automatically adds situation based constraints to ensure that users can only see results that they are allowed to access. We have validated our framework by applying it to two dynamic use cases: maritime search and rescue operations and contact tracing for surveillance of a contagious disease. This paper details our implemented solution and experimental results of the two use cases. Our framework can be adopted by organizations that need to share sensitive data securely during dynamic, limited duration scenarios.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于查询重写的联邦数据即服务系统态势感知访问控制框架
组织通常需要以安全和灵活的方式共享与任务相关的数据。例如,追踪covid - 19等传染病的接触者,海上搜救行动,或为合同创建协作投标。在这种情况下,访问数据的能力可能需要根据任务的情况动态变化(例如,某人的疾病检测结果是否呈阳性,船舶是否遇险,或需要创建具有特定属性的出价)。我们提出了一个新的框架,通过使用语义web技术在联邦数据即服务体系结构中实现态势感知访问控制。我们的框架允许分布式查询重写和语义推理,自动添加基于情况的约束,以确保用户只能看到他们被允许访问的结果。我们通过将其应用于两个动态用例来验证我们的框架:海上搜索和救援行动以及为监测传染病而追踪接触者。本文详细介绍了我们实现的解决方案和两个用例的实验结果。需要在动态、有限持续时间的场景中安全地共享敏感数据的组织可以采用我们的框架。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Message from the SCC 2020 Chairs A Process Convergence Approach for Crossover Services based on Message Flow Partition and Merging SCC 2020 Organizing Commitee An IoT-owned Service for Global IoT Device Discovery, Integration and (Re)use PETA: Privacy Enabled Task Allocation
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1