BlueSky: Activity Control: A Vision for "Active" Security Models for Smart Collaborative Systems
Tanjila Mawla, Maanak Gupta, and Ravi Sandhu

TL;DR
This paper advances activity-centric access control (ACAC) models for smart collaborative systems, emphasizing active, real-time security decisions that adapt to ongoing device activities within interconnected cyber-physical ecosystems.
Contribution
It introduces core components of ACAC, compares it with existing models, and proposes a hierarchical structure that incorporates activity notions and aligns with Zero Trust principles.
Findings
ACAC supports active, real-time access control decisions.
Hierarchical ACAC models incorporate activity states and properties.
ACAC aligns with Zero Trust for enhanced security in smart ecosystems.
Abstract
Cyber physical ecosystem connects different intelligent devices over heterogeneous networks. Various operations are performed on smart objects to ensure efficiency and to support automation in smart environments. An Activity (defined by Gupta and Sandhu) reflects the current state of an object, which changes in response to requested operations. Due to multiple running activities on different objects, it is critical to secure collaborative systems considering run-time decisions impacted due to related activities (and other parameters) supporting active enforcement of access control decision. Recently, Gupta and Sandhu proposed Activity-Centric Access Control (ACAC) and discussed the notion of activity as a prime abstraction for access control in collaborative systems. The model provides an active security approach that considers activity decision factors such as authorizations,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
