Cyber physical ecosystem connects different intelligent devices over heterogeneous networks. Various operations are performed on smart objects to ensure efficiency and to support automation in smart environments. An Activity (defined by Gupta and Sandhu) reflects the current state of an object, which changes in response to requested operations. Due to multiple running activities on different objects, it is critical to secure collaborative systems considering run-time decisions impacted due to related activities (and other parameters) supporting active enforcement of access control decision. Recently, Gupta and Sandhu proposed Activity-Centric Access Control (ACAC) and discussed the notion of activity as a prime abstraction for access control in collaborative systems. The model provides an active security approach that considers activity decision factors such as authorizations, obligations, conditions, and dependencies among related device activities. This paper takes a step forward and presents the core components of an ACAC model and compares with other security models differentiating novel properties of ACAC. We highlight how existing models do not (or in limited scope) support `active' decision and enforcement of authorization in collaborative systems. We propose a hierarchical structure for a family of ACAC models by gradually adding the properties related to notion of activity and discuss states of an activity. We highlight the convergence of ACAC with Zero Trust tenets to reflect how ACAC supports necessary security posture of distributed and connected smart ecosystems. This paper aims to gain a better understanding of ACAC in collaborative systems supporting novel abstractions, properties and requirements.
翻译:• 最近,Gupta和Sandhu提议的活动中心访问控制(ACAC)对智能物体进行了各种操作,以确保效率并支持智能环境中的自动化。一项活动(由Gupta和Sandhu界定)反映了一个物体的现状,该活动反映了一个物体的当前状态,该物体因要求的行动而有所变化。由于在不同物体上开展多种运行活动,因此必须确保合作系统考虑到由于相关活动(和其他参数)而影响运行时间决定,以支持积极执行出入控制决定。最近,Gupta和Sandhu提议的活动中心访问控制(ACAC)支持积极执行。我们建议,在合作系统中,将活动的概念作为访问控制的主要抽象概念。该模型提供了一种积极的安全方法,考虑到活动决定因素,如授权、义务、条件和相关装置活动之间的依赖性。由于在不同物体上开展多种运行活动,本文件向前迈出了一步,介绍了ACAC模式的核心组成部分,并与区别ACAC的新特性的其他安全模式相比较。我们强调,现有模式如何(或范围有限)不支持“积极”决定和执行合作系统的授权。我们建议,为ACACA模式的大家庭提出一个等级结构结构结构结构,逐步支持与Secal Instional Instal Instal asion asion 支持Syal real deliview。