Article (Périodiques scientifiques)
Conviviality-driven access control policy
EL KATEB, Donia; Zannone, N.; MOAWAD, Assaad et al.
2015In Requirements Engineering, 20 (4), p. 363-382
Peer reviewed
 

Documents


Texte intégral
Conviviality-Driven Access Control Policy.pdf
Postprint Éditeur (3.93 MB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Access control; Conviviality; Negotiable and non-negotiable authorizations; Requirement model; Intelligent agents; Multi agent systems; Access control mechanism; Access control policies; Ambient assisted living; Methodological frameworks; Requirement modeling; Social science concepts
Résumé :
[en] Nowadays many organizations experience security incidents due to unauthorized access to information. To reduce the risk of such incidents, security policies are often employed to regulate access to information. Such policies, however, are often too restrictive, and users do not have the rights necessary to perform assigned duties. As a consequence, access control mechanisms are perceived by users as a barrier and thus bypassed, making the system insecure. In this paper, we draw a bridge between the social concept of conviviality and access control. Conviviality has been introduced as a social science concept for ambient intelligence and multi-agent systems to highlight soft qualitative requirements like user-friendliness of systems. To bridge the gap between conviviality and security, we propose a methodological framework for updating and adapting access control policies based on conviviality recommendations. Our methodology integrates and extends existing techniques to assist system designers in the derivation of access control policies from socio-technical requirements of the system, while taking into account the conviviality of the system. We illustrate our framework using the Ambient Assisted Living use case from the HotCity of Luxembourg. © 2014, Springer-Verlag London.
Disciplines :
Sciences informatiques
Identifiants :
eid=2-s2.0-84941996526
Auteur, co-auteur :
EL KATEB, Donia ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > Computer Science and Communications Research Unit (CSC)
Zannone, N.;  Security Group, Department of Mathematics and Computer Science, Eindhoven University of Technology, P.O. Box 513, Eindhoven, Netherlands
MOAWAD, Assaad ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
CAIRE, Patrice ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
NAIN, Grégory ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Mouelhi, T.;  Interdisciplinary Centre for Security, Reliability and Trust (SnT), University of Luxembourg, Luxembourg City, Luxembourg
LE TRAON, Yves ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Co-auteurs externes :
yes
Langue du document :
Anglais
Titre :
Conviviality-driven access control policy
Date de publication/diffusion :
2015
Titre du périodique :
Requirements Engineering
ISSN :
0947-3602
Maison d'édition :
Springer-Verlag London Ltd
Volume/Tome :
20
Fascicule/Saison :
4
Pagination :
363-382
Peer reviewed :
Peer reviewed
Organisme subsidiant :
NWO - Nederlandse Organisatie voor Wetenschappelijk Onderzoek
Disponible sur ORBilu :
depuis le 03 avril 2016

Statistiques


Nombre de vues
220 (dont 6 Unilu)
Nombre de téléchargements
255 (dont 3 Unilu)

citations Scopus®
 
7
citations Scopus®
sans auto-citations
5
OpenCitations
 
2
citations OpenAlex
 
5
citations WoS
 
4

Bibliographie


Publications similaires



Contacter ORBilu