In highly dynamic and distributed computing environments (e.g., Cloud, Internet of Things (IoT), mobile, edge), robust access and usage control of assets is crucial. Since assets can be replicated in various locations on heterogeneous platforms and dynamic networks with unknown or partially authenticated users, the need for a uniform control mechanism is essential. The theory of Usage Control (UCON) is an example of such a mechanism to regulate access and usage of resources based on expressive polices and a loosely-coupled enforcement technology. However, in complex socio-technical systems, concerns about scalability, performance, modularity often arise, and existing UCON models and frameworks cannot meet such requirements. To tackle these concerns, we introduce UCON+, an improvement over existing UCON models, which adds continuous monitoring before granting and after revoking authorizations as well as policy administration and delegation. This chapter aggregates our recent contributions on the conceptual, architectural, and implementation level of UCON+, and provides a comprehensive reference to describe the current state-of-the-art and the novelties of UCON+.

UCON+: Comprehensive Model, Architecture and Implementation for Usage Control and Continuous Authorization / Hariri, Ali; Ibrahim, Amjad; Alangot, Bithin; Bandopadhyay, Subhajit; La Marra, Antonio; Rosetti, Alessandro; Joumaa, Hussein; Dimitrakos, Theo. - (2023), pp. 209-226. [10.1007/978-3-031-16088-2_10]

UCON+: Comprehensive Model, Architecture and Implementation for Usage Control and Continuous Authorization

Hariri, Ali
Primo
;
Joumaa, Hussein;
2023-01-01

Abstract

In highly dynamic and distributed computing environments (e.g., Cloud, Internet of Things (IoT), mobile, edge), robust access and usage control of assets is crucial. Since assets can be replicated in various locations on heterogeneous platforms and dynamic networks with unknown or partially authenticated users, the need for a uniform control mechanism is essential. The theory of Usage Control (UCON) is an example of such a mechanism to regulate access and usage of resources based on expressive polices and a loosely-coupled enforcement technology. However, in complex socio-technical systems, concerns about scalability, performance, modularity often arise, and existing UCON models and frameworks cannot meet such requirements. To tackle these concerns, we introduce UCON+, an improvement over existing UCON models, which adds continuous monitoring before granting and after revoking authorizations as well as policy administration and delegation. This chapter aggregates our recent contributions on the conceptual, architectural, and implementation level of UCON+, and provides a comprehensive reference to describe the current state-of-the-art and the novelties of UCON+.
2023
UCON+: Comprehensive Model, Architecture and Implementation for Usage Control and Continuous Authorization
New York
Springer, Cham
978-3-031-16087-5
978-3-031-16088-2
Hariri, Ali; Ibrahim, Amjad; Alangot, Bithin; Bandopadhyay, Subhajit; La Marra, Antonio; Rosetti, Alessandro; Joumaa, Hussein; Dimitrakos, Theo...espandi
UCON+: Comprehensive Model, Architecture and Implementation for Usage Control and Continuous Authorization / Hariri, Ali; Ibrahim, Amjad; Alangot, Bithin; Bandopadhyay, Subhajit; La Marra, Antonio; Rosetti, Alessandro; Joumaa, Hussein; Dimitrakos, Theo. - (2023), pp. 209-226. [10.1007/978-3-031-16088-2_10]
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11572/364258
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 3
  • ???jsp.display-item.citation.isi??? ND
social impact