Browse > Article

A RBAC-based Access Control Framework in OSGi Service Platform  

Cho, Eun-Ae (고려대학교 컴퓨터학과)
Moon, Chang-Joo (건국대학교 항공우주공학)
Baik, Doo-Kwon (고려대학교 컴퓨터학과)
Abstract
Recently, according to the network environment, there are many researches for home network. Nowadays, in home network, the method that access control policy is managed for each home device by using ACL is popular, and EAM (Extranet access management) is applied as a solution. In addition, the research about secure OS is ongoing based on open operating system and the research of user authentication mechanisms for home network using home server is also in progress. However, these researches have some problems as follows; First, the transmission scope of expected access technology in home network is wide, so unauthenticated outside terminal can access the home network. Second, user is inconvenient because user need to set the necessary information for each device. Third, user privacy and convenience are not considered. OSGi provides a service platform for heterogeneous technologies in home network environment. Here, user access control is one of the core parts which should have no problems such as above items, but there are no concrete researches yet. Thus in this paper, we propose an access control policy management framework and access control operation based on RBAC for user access control in home network environment in which OSGi service platform is operated. First, we list the consideration which is not clearly mentioned in OSGi standard, and then we solve these above problems through new framework. In addition, we propose the effective and economical operation method which reduces the policy change frequency for user access control by using RBAC concept though limited resource of home gateway. Besides, in this paper, these proposed policies are defined separately as user-role assignment policy and permission-role assignment policy, and user decide their own policies. In conclusion, we provide the scheme to enhance the user convenience and to solve the privacy problem.
Keywords
Access Control; Authorization; RBAC; OSGi;
Citations & Related Records
Times Cited By KSCI : 2  (Citation Analysis)
연도 인용수 순위
1 전경석, 문창주, 박대하, 백두권 ' OSGi서비스 플랫폼 환경에서의 사용자 인증 메커니즘', 정보과학회논문지, 제9권 제2호, pp. 191-204, 2003
2 한국정보통신기술협회, 홈서버 중심의 홈네트워크 사 용자 인증 메커니즘, 정보통신 단체표준 TTAS.KO- 12.0030, 2005
3 Dae-Ha Park, Doo-Kwon Baik, OSSEM: a security model for OSGi service framework, 7th World Multi-conference on Systemics, Cybernetics and Informatics (SCI2003), Orlando(USA), pp. 189-194, 2003
4 Harry Chen, Tim Finin, Anupam Joshi, An Ontology for Context-Aware Pervasive Computing Environment, Workshop on Ontologies and Distributed Systems, IJCAI-2003, Acapulco(Mexico), 2003
5 박세현, 유비쿼터스 홈을 위한 상황인지 서비스 기술, TTA 저널, 2005
6 RDF Resource Description Framework, http://www.w3.org/RDF/
7 Joon S. Park, Ravi Sandhu, Gail-Joon Ahn. Rolebased access control on the Web. ACM Transactions on Information and System Security (TISSEC), Vol.4, No.1, pp. 37-71, 2001   DOI
8 Sylvia Osborn, Ravi Sandhu, Qamar Munawer, Configuring Role-Based Access Control to Enforce Mandatory and Discretionary Access Control Policies, ACM Transactions on Information and System Security, Vol.3, No.2, pp. 85-106, 2000   DOI
9 Joon S. Park and Ravi S. Sandhu, Gail-Joon Ahn, Role-Based Access Control on the Web, ACM Transactions on Information and System Security, Vol.4, No.1, pp. 37-71, 2001   DOI
10 Eun-Ae Cho, Chang-Joo Moon, Dae-Ha Park, Doo-Kwon Baik, Access Control Policy Management Framework based on RBAC in OSGi Service Platform, 6th IEEE International Conference on Computer and Information Technology (CIT06), Seoul(Korea), 2006
11 Anne Anderson, Java Access Control Mechanisms, Technical report, Sun Microsystems, ' http://lists. oasis-open.org/archives/xacml/200201/pdf00000.pdf,' 2002
12 Chang-Joo Moon, Dae-Ha Park, Seong-Jin Park, Doo-Kwon Baik, Symmetric RBAC Model that Takes the Separation of Duty and Role Hierarchies into Consideration, Computers & Security, Vol.23, pp. 126-136, 2004   DOI   ScienceOn
13 OSGi 'OSGi Service Platform Release 3 Specification' http://www.osgi.org/. 2006
14 Tao Gu, Hung Keng Pung, Da Qing Zhang, Toward an OSGi-Based Infrastructure for Context- Aware Applications, IEEE Pervasive Computing, Vol.3, No.4, pp. 66-74, 2004
15 OWL Web Ontology Language, http://www.w3.org/TR./owl-ref
16 David F. Ferraiolo, Role-Based Access Control, Artech House, Computer Security, 2003
17 황지온, 유비쿼터스 환경에 적합한 차세대 홈네트워크 를 위한 온톨로지 지식서비스 모델 연구, 중앙대 대학 원, 석사학위논문, 2005
18 SAX(Simple API for XML) 2.0.1, ' http://www. saxproject.org/,' 2006
19 Eun-Ae Cho, Chang-Joo Moon, Dae-Ha Park, Doo-Kwon Baik, An Effective Policy Management Framework Using RBAC model for Service Platform based on Components, 4th International Conference on Software Engineering Research, Management and Applications (SERA2006), Seattle (USA), pp. 281-287, 2006
20 김영갑, 문창주, 박대하, 백두권, ' OSGi 서비스 플랫폼 환경에서의 서비스 번들 인증 메커니즘의 검증 및 구 현', 정보과학회논문지, 제31권 제1호, pp. 27-40, 2004
21 Chang-Joo Moon, Woojin Paik, Young-Gab Kim, Ju-Hum Kwon, The Conflict Detection between Permission Assignment Constraints in Role-Based Access Control, Lecture Notes in Computer Science, LNCS 3822, pp. 265-278, 2005
22 John Barkley, Comparing simple role based access control models and access control lists, 2nd ACM workshop on Role-based access control, Fairfax (USA), pp. 127-132, 1997
23 이준호, 임경식, 원유재, XACML 기반 홈 네트워크 접근제어 시스템의 설계 및 구현, 한국정보처리학회 논문지 C Vol.13-C, No.05, pp. 0549-0558, 2006   과학기술학회마을   DOI
24 Tao Gu, Xiao Hang Wang, Hung Keng Pung, Da Qing Zhang, An Ontology-based Context Model in Intelligent Environments, Communication Networks and Distributed Systems Modeling and Simulation Conference (CNDS 2004), pp. 270-275, 2004
25 NSA, Security Enhanced Linux, ' http://www.nsa.gov/ selinux'
26 한종욱, 홈네트워크 인증 및 접근제어기술, 홈네트워크 시큐리티 포럼(HNSF), 2004
27 김재현, 무선 홈 네트워크 환경의 계층별 접근제어, 한국전자통신연구원, 2005
28 Ravi S. Sandhu, Edward J. Coynek, Hal L. Feinsteink, Charles E. Youmank, Role-Based Access Control Models, IEEE Computer, Vol.29, No.2, pp. 38-47, 1996
29 Joon S. Park and Ravi S. Sandhu. RBAC on the Web by smart certificates, 4th ACM Workshop on Role-Based Access Control (RBAC), pp. 1-9, 1999
30 DOM(Document Object Model), ' http://www.w3.org/ DOM/,' 2006
31 홈네트워크보안연구팀, 홈네트워크를 위한 인증 및 접근권한 제어기술개발, 한국전자통신연구원, 2005
32 Joon S. Park and Ravi S. Sandhu, Smart certificates: Extending X.509 for secure attribute services on the Web, 22nd National Information Systems Security Conference (NISSC), Crystal City(Virginia), pp. 337-348, 1999
33 Ravi S. Sandhu, David F. Ferraiolo, Richard Kuhn, The NIST Model for Role-Base Access Control: Toward A Unified Standard, 5th ACM Workshop on Role Based Access Control, Berlin (Germany), pp. 47-63, 2000
34 Ant Allan,' Extranet Access Management(EAM): Perspective,' Gartner, 2001