{"title":"Context-based security management for multi-agent systems","authors":"R. Montanari, A. Toninelli, J. Bradshaw","doi":"10.1109/MASSUR.2005.1507050","DOIUrl":null,"url":null,"abstract":"Policies are being increasingly used for controlling the behavior of complex multi-agent systems. The use of policies allows administrators to specify both agent permissions and duties without changing source code or requiring the consent or cooperation of the agents being governed. However, policy-based control can encounter difficulties when applied to agents that act in pervasive environments characterized by frequent and unpredictable changes. In this case, policies cannot be all specified a priori to face any operative run time situation, but require continuous adjustments to allow agents to behave in a contextually appropriate manner. Current approaches to policy representation have been restrictive in many ways, as they typically follow a subject-centric model, which assigns agent permissions and obligations on the basis of agent role/identity information. However, in the new pervasive scenario the roles/identities of interacting agents may not be known a-priori and most important, may not be informative or sufficiently trustworthy. We claim that the design of policy-based agent systems for pervasive environments requires a paradigm shift from subject-centric to context-centric policy models. This paper discusses some issues concerning the specification and enforcement of context-driven policies and presents a novel context-based policy approach that considers context as a first-class principle to guide both policy specification and enforcement. In this perspective, \"context\" explicitly appears in the specification of security policies and context changes trigger the evaluation process of applicable agent permissions and obligations.","PeriodicalId":391808,"journal":{"name":"IEEE 2nd Symposium on Multi-Agent Security and Survivability, 2005.","volume":"51 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-09-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"25","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE 2nd Symposium on Multi-Agent Security and Survivability, 2005.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MASSUR.2005.1507050","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 25
Abstract
Policies are being increasingly used for controlling the behavior of complex multi-agent systems. The use of policies allows administrators to specify both agent permissions and duties without changing source code or requiring the consent or cooperation of the agents being governed. However, policy-based control can encounter difficulties when applied to agents that act in pervasive environments characterized by frequent and unpredictable changes. In this case, policies cannot be all specified a priori to face any operative run time situation, but require continuous adjustments to allow agents to behave in a contextually appropriate manner. Current approaches to policy representation have been restrictive in many ways, as they typically follow a subject-centric model, which assigns agent permissions and obligations on the basis of agent role/identity information. However, in the new pervasive scenario the roles/identities of interacting agents may not be known a-priori and most important, may not be informative or sufficiently trustworthy. We claim that the design of policy-based agent systems for pervasive environments requires a paradigm shift from subject-centric to context-centric policy models. This paper discusses some issues concerning the specification and enforcement of context-driven policies and presents a novel context-based policy approach that considers context as a first-class principle to guide both policy specification and enforcement. In this perspective, "context" explicitly appears in the specification of security policies and context changes trigger the evaluation process of applicable agent permissions and obligations.