This document proposes an adaptive security model for risk management using spatial data. The model uses attribute-based access control and allows security rules and authorizations to change dynamically based on risks detected in the environment. The security model includes subjects, objects, actions, contexts and handles adaptivity using an event-condition-action approach. When risks are detected, the appropriate context is activated, subject/object attributes and authorizations may change. The model is designed to authorize risk management teams appropriately based on dynamic environmental conditions. XACML is used to define the policies and implement the adaptive access control. Future work includes further integrating spatial data and handling policy conflicts during context switching.
Related topics: