LAPSE:2023.9214
Published Article

LAPSE:2023.9214
Context-Aware Policy Analysis for Distributed Usage Control
February 27, 2023
Abstract
To boost data spaces and benefit from the great opportunities that they present, data sovereignty must be provided by Distributed Usage Control (DUC). Assuming that DUC will be managed by implementing and enforcing policies, notable efforts have already been undertaken in the context of Access Control (AC) regarding policy analysis due to the impact of low-quality policies on security. In this regard, this paper proposes that policy analysis in the DUC context should be understood as an extension of the AC, which is further affected by other challenging features, chief among which are context-aware control and extended control through action requirements. This paper presents a novel Context-Aware Policy Analysis (CAPA) algorithm for detecting inconsistencies and redundancies for DUC policies by supporting a large set of heterogeneous conditions. In this regard, the dependent relationship of conditions is formulated which will lead to more efficient conflict detection. By implementing this concept, a novel tree structure that combines a resource and a policy structure is presented to search for and compare relevant rules from policies. Built on the tree structure and through the formalization of rule conflicts, CAPA is developed and the security and performance it provides is tested in a wind energy use case.
To boost data spaces and benefit from the great opportunities that they present, data sovereignty must be provided by Distributed Usage Control (DUC). Assuming that DUC will be managed by implementing and enforcing policies, notable efforts have already been undertaken in the context of Access Control (AC) regarding policy analysis due to the impact of low-quality policies on security. In this regard, this paper proposes that policy analysis in the DUC context should be understood as an extension of the AC, which is further affected by other challenging features, chief among which are context-aware control and extended control through action requirements. This paper presents a novel Context-Aware Policy Analysis (CAPA) algorithm for detecting inconsistencies and redundancies for DUC policies by supporting a large set of heterogeneous conditions. In this regard, the dependent relationship of conditions is formulated which will lead to more efficient conflict detection. By implementing this concept, a novel tree structure that combines a resource and a policy structure is presented to search for and compare relevant rules from policies. Built on the tree structure and through the formalization of rule conflicts, CAPA is developed and the security and performance it provides is tested in a wind energy use case.
Record ID
Keywords
conditions, data sovereignty, distributed usage control, energy data, policy quality
Subject
Suggested Citation
Gil G, Arnaiz A, Higuero M, Diez FJ, Jacob E. Context-Aware Policy Analysis for Distributed Usage Control. (2023). LAPSE:2023.9214
Author Affiliations
Gil G: Tekniker, Basque Research and Technology Alliance (BRTA), Iñaki Goenaga 5, 20600 Eibar, Spain [ORCID]
Arnaiz A: Tekniker, Basque Research and Technology Alliance (BRTA), Iñaki Goenaga 5, 20600 Eibar, Spain [ORCID]
Higuero M: Escuela de Ingeniería de Bilbao, Plaza Ingeniero Torres Quevedo 1, 48013 Bilbao, Spain [ORCID]
Diez FJ: Tekniker, Basque Research and Technology Alliance (BRTA), Iñaki Goenaga 5, 20600 Eibar, Spain
Jacob E: Escuela de Ingeniería de Bilbao, Plaza Ingeniero Torres Quevedo 1, 48013 Bilbao, Spain [ORCID]
Arnaiz A: Tekniker, Basque Research and Technology Alliance (BRTA), Iñaki Goenaga 5, 20600 Eibar, Spain [ORCID]
Higuero M: Escuela de Ingeniería de Bilbao, Plaza Ingeniero Torres Quevedo 1, 48013 Bilbao, Spain [ORCID]
Diez FJ: Tekniker, Basque Research and Technology Alliance (BRTA), Iñaki Goenaga 5, 20600 Eibar, Spain
Jacob E: Escuela de Ingeniería de Bilbao, Plaza Ingeniero Torres Quevedo 1, 48013 Bilbao, Spain [ORCID]
Journal Name
Energies
Volume
15
Issue
19
First Page
7113
Year
2022
Publication Date
2022-09-27
ISSN
1996-1073
Version Comments
Original Submission
Other Meta
PII: en15197113, Publication Type: Journal Article
Record Map
Published Article

LAPSE:2023.9214
This Record
External Link

https://doi.org/10.3390/en15197113
Publisher Version
Download
Meta
Record Statistics
Record Views
218
Version History
[v1] (Original Submission)
Feb 27, 2023
Verified by curator on
Feb 27, 2023
This Version Number
v1
Citations
Most Recent
This Version
URL Here
https://psecommunity.org/LAPSE:2023.9214
Record Owner
Auto Uploader for LAPSE
Links to Related Works
