Alex Chiquito

dblp:276/3098 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
4since 2021 · last 2023
0000-0002-2654-2292ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 3 first-author · 4 since 2021
YearPublicationVenuePosition
2023 Automated Management of Attribute-Based Policies for Access Control Using Tag-Matching
abstract
Data sharing is becoming increasingly important as organizations seek to improve their operations and gain a competitive advantage. The data sharing between organizations, stakeholders, and even internal teams requires access control policies that define who can access what data, under what circumstances, and for what purposes. Attribute-based access control (ABAC) provides a flexible and fine-grained mechanism for enforcing such policies, preventing data leakage, and improving security and compliance. A challenge is that these policies should be able to support the agility and adaptability of constantly evolving modern industrial systems, where new data sources, services, and users are frequently added and removed. As the number of data sources and associated policies grows, the manual management of ABAC policies in evolving systems becomes a bottleneck, which prevents the adoption of fine-grained access control mechanisms. This paper presents a model based on tag-matching to automate the process of connecting new data sources and users to existing access control policies. In the proposed model, tag-matching means matching metadata elements to policy attributes to reduce the administrative work of managing access policies. The model takes advantage of the identity abstraction of ABAC policies to connect existing rules between attributes and the target resource or user. We present a proof-of-concept implementation of the tag-matching model in Eclipse Arrowhead and provide an evaluation of the proposed solution.
Alex Chiquito, Ulf Bodin, Olov Schelén
IECON1
2022 Automated usage control for secure data sharing based on Ricardian contracts
abstract
Data is important for the industry to take advantage of digitalization, realize automation, assure quality, and more. Values from data are not only created individually by companies, but also in eco-systems in which data is shared among participating organizations. Secure data sharing is essential in such eco-systems to prevent unauthorized access and use of the data. Usage control extends traditional access control with restrictions concerned with requirements that pertain to data processing contractual obligations, rather than data access provisions only. Thus, usage control is relevant in the context of intellectual property protection, compliance with regulations, and digital rights management. This paper presents a method to negotiate contractual obligations and access provisions, and automatically enforce those provisions with access control. Finalized negotiations establish Ricardian contracts at two levels; a superordinate level with a connected subordinate level. These contracts contain provisions in terms of access control attributes. Using our implementation of a negotiation engine we demonstrate the automatic creation of NIST Next Generation Access Control (NGAC) access control policies. Our negotiation engine uses a lightweight model for the storage of an unforgeable and immutable log of the established contracts based on digital signatures and hashing.
Eric Chiquito, Alex Chiquito, Ulf Bodin, Kåre Synnes
IECON2
2021 Application-scoped Access Control for the Construction Industry
abstract
The construction industry is characterized by its extensive and dynamic collaborations between contractors providing various services and expertise. In such eco-systems, the secure sharing of information, data and equipment challenges the access control needs to be application agnostic. Furthermore, it needs fine-grained access policies including means for abstraction to ease administration, and support for delegated authorization in Service-Oriented Architecture (SOA) based systems. In this paper, we explore the use of delegated access using OAuth 2.0 with Attribute-Based Access Control (ABAC) for the collaborative sharing of equipment at construction sites. In particular, we investigate the use of contextual attributes to capture the dynamic aspects, such as location and urgency, in the booking of construction lifts. Through this study, we propose a solution based on the IoT Application-scoped Access Control as a Service (IAACaaS) architecture model combined with NIST Next Generation Access Control (NGAC). We present an architecture for a general Identity and Access Management (IAM) system for the construction industry, and provide a design and guide for implementation of this architecture in terms how key functionalities should be captured as reusable micro-services. Moreover, we describe how these micro-services can be combined to make the system a general and reusable solution providing access control for collaborative sharing of data, information and equipment at construction sites.
Ulf Bodin, André Christoffersson, Alex Chiquito, Johan Rodahl, Kåre Synnes
ETFA3
2021 Fine-grained Access Control for Time-Series Databases using NGAC
abstract
Industrial Internet of Things (IIoT) and Industry 4.0 rely heavily on data for reasons such as production follow-up, planning and optimization. Industrial data come in large volumes from production logs and sensors whereof some data carries business and strategic value, sensitive information, or a combination of both. Such data must be protected from unauthorized access, but also be easy to access for authorized users to facilitate work to gain business and operational values from the data. The efficient creation and maintenance of access policies for secure data sharing is hence essential, but unfortunately also challenging in terms of the complexity and administrative effort for fine-grained such. Attribute-based access control (ABAC) such as the Next Generation Access Control (NGAC) provides efficient models for handling access policies. Existing access control models fail however to provide a simple and easy-to-maintain policy language capable of efficiently enforcing fine-grained access control policies for large volumes of time-series data. In this paper, we propose extensions to NGAC based on filter strings that facilitates efficient enforcement of row-level value and time constraint policies for time-series data. We evaluate two approaches for storing and retrieving these filter strings and provide a qualitative and quantitative discussion of the results.
Alex Chiquito, Ulf Bodin, Olov Schelén
INDIN1
2020 Access Control Model for Time Series Databases using NGAC
abstract
In Industry 4.0 and Industrial Internet of Things (IIoT), large amounts of time-series sensor data is collected from devices and machines. Industrial data typically contain sensitive information that may harm the data owner should it leaks. Although such risks exist, selected data frequently needs to be shared in partner eco-systems to take advantage of expertise in analyzing the data and to synchronize between partners collaborating in the production system. Consequently, access control must support efficient data selection and sharing. The access control should be capable of managing and enforcing access policies for different operations and with different levels of granularity, while being simple to properly maintain and potentially automate. In this paper we examine the possible use of Next-Generation Access Control (NGAC) for such access control. NGAC is an attribute-based access control (ABAC) standard based on relations between data elements to create, manage and enforce access control policies. We propose an Access control model that maps the NGAC policy language to the query language of time-series databases to facilitate a secure and efficient data sharing system for IIoT sensor data.
Alex Chiquito, Ulf Bodin, Olov Schelén
ETFA1