6 CONCLUSIONS
In this paper, we proposed a generic ontology that
models entities, their interrelationships and access
control policies, and it can be easily extended for
specific environments. To show its applicability, we
extended it for two large and open scenarios: OSNs
and the cloud. We also illustrated through examples
how the definition of rules and the management of
access control are greatly simplified for system
administrators, because they can be intuitively made
at a conceptual –class- level. Then, specific (and
dynamic) rules can be automatically inferred
according to the specific entities, which would also be
likely dynamic in open scenarios such as those
tackled in the paper.
As future work, we plan to extend the generic
ontology to other specific scenarios (e.g., business
organizations) and propose automatic and scalable
inference mechanisms to manage other aspects of
access control (e.g., delegation). At this respect we
will study and formalize more complex inference
rules that exploit the ontological structure, and
develop algorithms to deal with cases in which policy
conflicts may appear. Moreover, we also plan to study
the interoperability issues that arise in access control
between heterogeneous systems and evaluate whether
our ontology-based mechanism (with its common
ontological backbone) may provide a suitable
solution to interoperate between rules and entities of
different scenarios.
ACKNOWLEDGEMENTS
This work was partly supported by the European
Commission under H2020 project CLARUS, by the
Spanish Ministry of Science and Innovation (through
projects CO-PRIVACY TIN2011-27076-C03-01 and
ICWT TIN2012-32757) and by the Government of
Catalonia (under grant 2014 SGR 537).
REFERENCES
Aimeur, E., S. Gambs, et al. (2010). Towards a Privacy-
Enhanced Social Networking Site. In ARES '10,
International Conference on Availability, Reliability,
and Security.
Beato, F., M. Kohlweiss, et al. (2009). Enforcing access
control in social networks. HotPETs: 1-10.
Ben-Fadhel, A., D. Bianculli, et al. (2015). "A
comprehensive modeling framework for role-based
access control policies." Journal of Systems and
Software 107: 110-126.
Carminati, B., E. Ferrari, et al. (2011). "Semantic web-
based social network access control." Computers &
Security 30 (2-3): 108-115.
Cheng, Y., J. Park, et al. (2012). A User-to-User
Relationship-Based Access Control Model for Online
Social Networks. Data and Applications Security and
Privacy XXVI, Springer Berlin Heidelberg. 7371: 8-24.
Choi, C., J. Choi, et al. (2014). "Ontology-based access
control model for security policy reasoning in cloud
computing." The Journal of Supercomputing 67(3):
711-722.
Cramer, M., J. Pang, et al. (2015). A Logical Approach to
Restricting Access in Online Social Networks.
Proceedings of the 20th ACM Symposium on Access
Control Models and Technologies. Vienna, Austria,
ACM: 75-86.
Daud, M. I., D. Sánchez, et al. (2015). Ontology-Based
Delegation of Access Control: An Enhancement to the
XACML Delegation Profile. Trust, Privacy and
Security in Digital Business. S. Fischer-Hübner, C.
Lambrinoudakis and J. López, Springer International
Publishing. 9264: 18-29.
Jin, X., R. Krishnan, et al. (2012). A Unified Attribute-
Based Access Control Model Covering DAC, MAC
and RBAC. Data and Applications Security and Privacy
XXVI. N. Cuppens-Boulahia, F. Cuppens and J.
Garcia-Alfaro, Springer Berlin Heidelberg. 7371: 41-
55.
Liu, C.-L. (2014). "Cloud service access control system
based on ontologies." Advances in Engineering
Software 69: 26-36.
Masoumzadeh, A. and J. Joshi (2010). "An ontology-based
access control model for social networking systems."
IEEE Social Computing (SocialCom): 751 – 759.
Mika, P. (2007). "Ontologies are us: A unified model of
social networks and semantics." Web Semantics:
Science, Services and Agents on the World Wide Web
5(1): 5-15.
Pang, J. and Y. Zhang (2014). A new access control scheme
for Facebook-style social networks. Ninth International
Conference on Availability, Reliability and Security
(ARES), 2014, IEEE: 1-10.
Smari, W. W., P. Clemente, et al. (2014). "An extended
attribute based access control model with trust and
privacy: Application to a collaborative crisis
management system." Future Generation Computer
Systems 31: 147-168.
Viejo, A., J. Castellà-Roca, et al. (2013). Preserving the
User’s Privacy in Social Networking Sites. Trust,
Privacy, and Security in Digital Business. S. Furnell, C.
Lambrinoudakis and J. Lopez, Springer Berlin
Heidelberg. 8058: 62-73.