AN INFRASTURCTURE FOR CONTEXT-AWARE AUTHORIZATION IN UBIQUITOUS COMPUTING ENVIRONMENTS
Context-awareness and security are critical issues in ubiquitous computing. In this paper we present a framework for context-aware authorization in ubiquitous computing environments. We present an architecture consisting of authorization infrastructure and context infrastructure. The authorization infrastructure makes decision to grant access rights based on both contexts and policies specified with a flexible language. The context infrastructure provides contexts at various levels of abstraction and enables context users to acquire contexts by submitting a query or using an event notification mechanism. The policy specification language allows one to authorize, prohibit, delegate, and revoke access rights. It also has constructs to package policies, resolve conflicts among policies, and specify the interaction with the context infrastructure.