Ulf Bodin, André Christoffersson, Alex Chiquito, Johan Rodahl, K. Synnes
{"title":"建筑行业的应用范围访问控制","authors":"Ulf Bodin, André Christoffersson, Alex Chiquito, Johan Rodahl, K. Synnes","doi":"10.1109/ETFA45728.2021.9613645","DOIUrl":null,"url":null,"abstract":"The construction industry is characterized by its extensive and dynamic collaborations between contractors providing various services and expertise. In such eco-systems, the secure sharing of information, data and equipment challenges the access control needs to be application agnostic. Furthermore, it needs fine-grained access policies including means for abstraction to ease administration, and support for delegated authorization in Service-Oriented Architecture (SOA) based systems. In this paper, we explore the use of delegated access using OAuth 2.0 with Attribute-Based Access Control (ABAC) for the collaborative sharing of equipment at construction sites. In particular, we investigate the use of contextual attributes to capture the dynamic aspects, such as location and urgency, in the booking of construction lifts. Through this study, we propose a solution based on the IoT Application-scoped Access Control as a Service (IAACaaS) architecture model combined with NIST Next Generation Access Control (NGAC). We present an architecture for a general Identity and Access Management (IAM) system for the construction industry, and provide a design and guide for implementation of this architecture in terms how key functionalities should be captured as reusable micro-services. Moreover, we describe how these micro-services can be combined to make the system a general and reusable solution providing access control for collaborative sharing of data, information and equipment at construction sites.","PeriodicalId":312498,"journal":{"name":"2021 26th IEEE International Conference on Emerging Technologies and Factory Automation (ETFA )","volume":"3 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-09-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Application-scoped Access Control for the Construction Industry\",\"authors\":\"Ulf Bodin, André Christoffersson, Alex Chiquito, Johan Rodahl, K. Synnes\",\"doi\":\"10.1109/ETFA45728.2021.9613645\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The construction industry is characterized by its extensive and dynamic collaborations between contractors providing various services and expertise. In such eco-systems, the secure sharing of information, data and equipment challenges the access control needs to be application agnostic. Furthermore, it needs fine-grained access policies including means for abstraction to ease administration, and support for delegated authorization in Service-Oriented Architecture (SOA) based systems. In this paper, we explore the use of delegated access using OAuth 2.0 with Attribute-Based Access Control (ABAC) for the collaborative sharing of equipment at construction sites. In particular, we investigate the use of contextual attributes to capture the dynamic aspects, such as location and urgency, in the booking of construction lifts. Through this study, we propose a solution based on the IoT Application-scoped Access Control as a Service (IAACaaS) architecture model combined with NIST Next Generation Access Control (NGAC). We present an architecture for a general Identity and Access Management (IAM) system for the construction industry, and provide a design and guide for implementation of this architecture in terms how key functionalities should be captured as reusable micro-services. Moreover, we describe how these micro-services can be combined to make the system a general and reusable solution providing access control for collaborative sharing of data, information and equipment at construction sites.\",\"PeriodicalId\":312498,\"journal\":{\"name\":\"2021 26th IEEE International Conference on Emerging Technologies and Factory Automation (ETFA )\",\"volume\":\"3 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-09-07\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 26th IEEE International Conference on Emerging Technologies and Factory Automation (ETFA )\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ETFA45728.2021.9613645\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 26th IEEE International Conference on Emerging Technologies and Factory Automation (ETFA )","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ETFA45728.2021.9613645","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Application-scoped Access Control for the Construction Industry
The construction industry is characterized by its extensive and dynamic collaborations between contractors providing various services and expertise. In such eco-systems, the secure sharing of information, data and equipment challenges the access control needs to be application agnostic. Furthermore, it needs fine-grained access policies including means for abstraction to ease administration, and support for delegated authorization in Service-Oriented Architecture (SOA) based systems. In this paper, we explore the use of delegated access using OAuth 2.0 with Attribute-Based Access Control (ABAC) for the collaborative sharing of equipment at construction sites. In particular, we investigate the use of contextual attributes to capture the dynamic aspects, such as location and urgency, in the booking of construction lifts. Through this study, we propose a solution based on the IoT Application-scoped Access Control as a Service (IAACaaS) architecture model combined with NIST Next Generation Access Control (NGAC). We present an architecture for a general Identity and Access Management (IAM) system for the construction industry, and provide a design and guide for implementation of this architecture in terms how key functionalities should be captured as reusable micro-services. Moreover, we describe how these micro-services can be combined to make the system a general and reusable solution providing access control for collaborative sharing of data, information and equipment at construction sites.