An Evolutionary Risk-based Access Control Framework for Enterprise File Systems

Shi Cho Cha, Yi Hsuan Hsuan, Kuo Hui Yeh, Takeshi Ishihara, Ohba Yoshihiro, Wei Nin Chen

研究成果: Conference contribution同行評審

1 引文 斯高帕斯(Scopus)

摘要

To enhance access control mechanisms, organizations need to monitor access requests issued from devices. There-fore, organizations can evaluate the trustworthiness or risks of the devices based on collected requests to adapt the access privileges. However, existing schemes usually do not address organizational authorization processes and may not be suitable for enterprise file systems. In light of this, this study proposes an Evolutionary Risk Adaptive Access Control (ERAAC) Framework for enterprise file systems. The proposed framework provides an extensible architecture for an organization to deploy different access control filters for different perspectives. An access control filter can filter out access requests based on access control policies. An organization can add a new access control filter without replacing its existing access control mechanism. In addition, the proposed framework enables organizations to define new risk labels for data entities, such as subjects and objects to be accessed, used in access control policies. The access control mechanism can adapt user privileges based on the risk labels. Even if organizations do not have enough data to generate risk labels, the organizations can set access control policies without risk labels. Therefore, the proposed framework enables organizations to progressively improve their access control mechanisms. To the best of our knowledge, the proposed framework is the first access control framework that can evolve with organizational maturity in risk management. This study also illustrates how the proposed framework satisfied the related tenets mentioned in NIST SP 800-207. Consequently, this study can hopefully contribute to helping an organization to implement zero trust architecture.

原文English
主出版物標題2022 IEEE 8th World Forum on Internet of Things, WF-IoT 2022
發行者Institute of Electrical and Electronics Engineers Inc.
ISBN(電子)9781665491532
DOIs
出版狀態Published - 2022
事件8th IEEE World Forum on Internet of Things, WF-IoT 2022 - Hybrid, Yokohama, 日本
持續時間: 26 10月 202211 11月 2022

出版系列

名字2022 IEEE 8th World Forum on Internet of Things, WF-IoT 2022

Conference

Conference8th IEEE World Forum on Internet of Things, WF-IoT 2022
國家/地區日本
城市Hybrid, Yokohama
期間26/10/2211/11/22

指紋

深入研究「An Evolutionary Risk-based Access Control Framework for Enterprise File Systems」主題。共同形成了獨特的指紋。

引用此