A Framework for Enforcement of Purpose Based Access Control

dc.contributor.advisorKarabatis, George
dc.contributor.authorJohnson, Shawn
dc.contributor.departmentInformation Systems
dc.contributor.programInformation Systems
dc.date.accessioned2021-01-29T18:11:55Z
dc.date.available2021-01-29T18:11:55Z
dc.date.issued2019-01-01
dc.description.abstractCurrent access control systems use static access control rules to enforce access to an object by checking appropriate permissions and then either granting or denying an access request. However, they are not flexible at all, therefore they are unable to incorporate and respond to a purpose of finer granularity, such as when a user may wish to automatically limit access to a database when individuals have some (one or more) suspected occurrences of mishandling personally identifiable information (PII) within an organization. The goal of this work is to create a purpose-based access control enforcement framework that adapts to changes in a system's environment based on the preferences of an information owner. This work enables an adaptive enforcement of access control in a system by adjusting and responding to changes in one's environment based on a set of user preferences. This work also enables accurate stateful characterization of access control enforcement rules and gives users a more fine-grained access control to a system compared to existing access control models. The impact of this work is an increase in the security outcomes of access control models and systems due to the incorporation of contextual personalization of the approach.
dc.formatapplication:pdf
dc.genredissertations
dc.identifierdoi:10.13016/m2uc74-zzyw
dc.identifier.other12041
dc.identifier.urihttp://hdl.handle.net/11603/20648
dc.languageen
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Information Systems Department Collection
dc.relation.ispartofUMBC Theses and Dissertations Collection
dc.relation.ispartofUMBC Graduate School Collection
dc.relation.ispartofUMBC Student Collection
dc.sourceOriginal File Name: Johnson_umbc_0434D_12041.pdf
dc.titleA Framework for Enforcement of Purpose Based Access Control
dc.typeText
dcterms.accessRightsDistribution Rights granted to UMBC by the author.
dcterms.accessRightsAccess limited to the UMBC community. Item may possibly be obtained via Interlibrary Loan thorugh a local library, pending author/copyright holder's permission.
dcterms.accessRightsThis item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author.

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Johnson_umbc_0434D_12041.pdf
Size:
1.74 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
JohnsonSFramework_Open.pdf
Size:
45.91 KB
Format:
Adobe Portable Document Format
Description: