Cross-layer Data-centric Usage Control
Enrico Lovat · 2015
Abstract. Usage control (UC) is concerned with what happens to data after access has been granted, and is usually defined on the grounds of events that, somehow, are related to data. Data may assume different representations within the system, possibly at several levels of abstrac-tion. This research aims at extending a generic event-driven UC model and its language [1] by the explicit distinction between data and repre-sentations of data. The resulting system will be able to enforce policies for single representations (e.g., delete f1.txt after thirty days) as well as for all representations of the same data at once (e.g., if f2.txt is a copy of f1.txt, also f2.txt will be deleted). To this end, different data-flow tracking approaches will be investigated. The result will be implemented, instan-tiated and evaluated in terms of security, precision and performance. 1