Authors:
Mitsuhiro Mabuchi
1
and
Koji Hasebe
2
Affiliations:
1
Toyota Motor Corporation, Japan
;
2
Department of Computer Science, University of Tsukuba, Japan
Keyword(s):
Access Control, Context-aware, Delegation, Capability, RBAC.
Abstract:
Various working styles, such as remote work, have become more common instead of working in one office. Moreover, to accelerate the development of new technologies, collaborations among multiple companies are increasing. Thus, most development projects are operating in dynamic environments, for example, dynamically changing teams, working from anywhere and at any time. To ensure security in such dynamic environments while maintaining efficiency, flexible and scalable access control is necessary. We previously proposed capability-role-based access control (CRBAC) that allows users to create capabilities for delegating authority across various domains without an administrator’s operation. However, in dynamic environments, a finer control is required based on where and when the authority is delegated or executed. In this paper, we propose an access control model called context-aware CRBAC (C2RBAC). This model is an extension of CRBAC obtained by introducing a mechanism of context-based r
estrictions on various operations regarding the delegation of authority by capabilities, such as time, place, and device. In this paper, we present a formal definition of C2RBAC and demonstrate its effectiveness using an example of collaborative development.
(More)