<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>A Security Contextualisation Framework for Digital Long-Term Preservation</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Kun Qian</string-name>
          <email>kun.qian@iti.cs.uni-magdeburg.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Maik Schott</string-name>
          <email>mschott@iti.cs.uni-magdeburg.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Christian Kraetzer</string-name>
          <email>kraetzer@iti.cs.uni-magdeburg.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Matthias Hemmje</string-name>
          <email>matthias.hemmje@fernuni-hagen.de</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Holger Brocks</string-name>
          <email>holger.brocks@fernuni-hagen.de</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Jana Dittmann</string-name>
          <email>jana.dittmann@iti.cs.uni-magdeburg.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Faculty of Computer Science, Otto-von-Guericke University Magdeburg</institution>
          ,
          <country country="DE">Germany</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Faculty of Mathematics and Computer Science, University of Hagen</institution>
          ,
          <country country="DE">Germany</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2011</year>
      </pub-date>
      <fpage>131</fpage>
      <lpage>142</lpage>
      <abstract>
        <p>Nowadays a growing amount of information not only exists in digital form but was actually born-digital. Digital long-term preservation becomes continuously important and is tackled by several international and national projects like the US National Digital Information Infrastructure and Preservation Program or the EU FP7 SHAMAN Integrated Project. The very essence of long-term preservation is the preserved data, which in turn requires an appropriate security model, which is so far often neglected in the preservation community. To address this problem, we extend the security relevant parts of the Open Archival Information System (OAIS) standard, in which security aspects are underspecified, by a conceptual framework for hierarchical security policy development based on given use-cases for a longterm archival system. The corresponding policies are then distributed and implemented by applying an iterative procedure to turn them into rules before these are then finally enforced. In this paper we describe how to construct a corresponding context model and derive such policies using the iterative approach to assure the system and data security.</p>
      </abstract>
      <kwd-group>
        <kwd>context model</kwd>
        <kwd>digital archive</kwd>
        <kwd>security policies</kwd>
        <kwd>system security</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction and motivation</title>
      <p>
        In this paper we perform security-oriented context modelling as well as policy
generation, implementation and enforcement focused on the security of a digital
longterm preservation environment which currently focuses on archiving texts (i.e. PDF
files) and digitised books (i.e. TIFF files). This context model is based on the
established OAIS ISO standard [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] as well as our previous work on digital long-term
archival system security. In [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] we describe a use-case-centric approach of deriving
operations, actions, objects, rights and roles from user-cases and how to employ these
for usage within a security model, e.g. an extended version of the Clark-Wilson model
[
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] including a syntactic-semantic integrity and authenticity verification approach.
This extended Clark-Wilson model is in [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] combined with an extended Information
Lifecycle Model [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] developed within the EU FP7 SHAMAN integrated project [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ]
to form a secure preservation framework for images and describing in detail the
integrity and authenticity verification processes.
      </p>
      <p>
        The work described in this paper aims at the development of a concept for
implementing and managing security for digital long-term preservation environments
of all kinds. The main instrument we foresee for this is the usage of policies, which of
course provides the following two challenges for this paper: First, to define a suitable
security-oriented context model for archival systems to act as basis for the policy
generation. Second, the (security) policies themselves have to be derived from the
context model. As a basis to address these two challenges we take use-cases based on
the OAIS standard [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] for digital archival systems.
      </p>
      <p>The main scientific contribution of this paper is the conception of a
contextualisation framework for context model and policy generation as well as
policy implementation and enforcement in the scope of multimedia archival systems
and data security.</p>
      <p>This paper is structured as follows: Firstly, in section 2 we present the
state-of-theart in methodologies for context modelling, policy generation, implementation and
enforcement in security relevant contexts. Then in section 3 we present our concept
for contextualisation and policy-based security realisation. At last in section 4 we
finally conclude and summarise this work.
2</p>
    </sec>
    <sec id="sec-2">
      <title>State-of-the-art</title>
      <p>This section introduces the state-of-the-art in methodologies for context modelling,
policy generation, implementation and enforcement in security relevant contexts. In
the scope of IT security, a good context model reflects the characteristics, the
intended application scenarios as well as corresponding threats for a system and
allows the design and implementation of policy controlled security mechanisms that
enforce the security aspects that are required to protect the application scenarios
against the threats.
2.1</p>
      <sec id="sec-2-1">
        <title>Methodologies for context modelling in IT security</title>
        <p>Context modelling, differing from other modelling methods, not only describes the
entities involved in a system but also explains how the entities are related with each
other by revealing their causality and relationships. The design of a context model can
either start from the very basic knowledge and be progressed by gradually adding
necessary information to achieve proper complexity (“bottom-up”) or start from the
vivid representation of the physical world and be progressed by gradually removing
redundancy to achieve the proper simplicity (“top-down”). Thus a well-designed
context model is at the same time a well balanced compromise between complexity
and simplicity, always being sophisticated enough to offer all the necessary details yet
still straightforward enough to be understood and applied.</p>
        <p>
          In the field of IT security context modelling plays an essential role in various
aspects. To meet the requirement of confidentiality, context modelling is for example
used to implement various access control policies. For example, Bhatti et al.
developed their model for web-services in [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ], based on an extended, trust-enhanced
version of Role Based Access Control (RBAC) framework that incorporates
contextbased access control. To recognise better the broader context in which security
requests arise, the Task Based Access Control (TBAC) extends the traditional
subject/object based access control models by including domains that contain
taskbased contextual information [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ]. To provide security for computing infrastructures in
which access decisions may depend on the context. Covington et al. developed a
context-aware access control by extending RBAC with the notion of environment
roles [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. For the aspect of authenticity, various models have been proposed. In the
scope of sensor forensics, Fridrich describes in [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ] a simplified sensor output model,
which contains the basic elements of the process of digital cameras acquiring images,
and then applied the model to derive a maximum likelihood estimator for the sensor
fingerprint, which can be used to identify digital cameras. In [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ] we propose a context
model for microphone recording by describing the involved signal processing pipeline
to reveal the influential factors that might be used as characteristics of different
microphone to contribute to microphone authentications. More often, when a context
model is developed aiming at assisting the construction of an information system,
multiple aspects of security issues need to be covered. For instance, the policy model
for clinical information systems developed by Anderson in [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ] focuses not only on
confidentiality and availability but also integrity. The context model described in this
paper for the application scenario of a secure digital long-term preservation archive
system is explained in detail in section 3. It takes not only confidentiality,
authenticity, integrity and availability but also non-repudiation in consideration.
        </p>
        <p>
          Currently, there exist three most prominent context modelling approaches [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]:
Object-role based context modelling originates from attempts to create sufficiently
formal models of context to support query processing and reasoning, as well as to
provide modelling constructs suitable for use in software engineering tasks such as
analysis and design. This approach is generally not applicable for hierarchical
structured modelling. Spatial context modelling focuses on location information. It is
well suited for context-aware applications that are mainly location-based, like many
mobile information systems. Ontology-based context modelling exploits the
representation and reasoning power to describe complex context data that cannot be
described by simple languages [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ]. It provides formal semantics to context data and
thus makes it available to check for consistency of the set of relationships describing a
context scenario as well as to recognise that a particular set of instances of basic
context data and their relationships actually reveals the presence of a more abstract
context characterisation. Compared to simpler approaches, it provides clear
advantages in terms of expressiveness and interoperability, which is the reason we use
ontology-based context modelling in our framework conception. In our concept the
ontology describes the entities in the security system as well as the relationships
among the entities, both of which are described by digital long-term preservation
usecases taken from the SHAMAN research project.
        </p>
        <p>
          Some evaluation criteria on the performance of context models have been proposed
in literature. For example, Strang et al. point out that the demands for context
modelling include distributed composition, partial validation, richness and quality of
information, (in-) completeness and ambiguity as well as level of formality and
applicability to existing environments [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ]. However these evaluating aspects are
rather based on the requirements of context modelling for ubiquitous computing, thus
suitable metrics for context models in the scope of IT security are still to be
developed. This point is not addressed here but reserved for our future work.
2.2
        </p>
      </sec>
      <sec id="sec-2-2">
        <title>Methodologies for security policy generation and enforcement</title>
        <p>
          Context models describe entities as well as the relationships among the entities in a
system. Good policies, as the systems governing mechanisms, are the foundation of
well-secured systems. Simply speaking, security policies define what in the system
should be protected [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ] to meet different aspects of security requirement depending
on the application scenario. Baskerville’s approach from [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ] can be considered as a
functional hierarchy of policies, using a three level division: meta-policies are
“policies about policies”, which declare plans for creating and maintaining security
policies; high-level policies are security policies which are high-level overall plans
embracing the general security goals and acceptable procedures; low-level policies
are defined information security methods of action that are selected from among
alternatives and applied based on given conditions that guide and determine present
and future information security decisions. This functional hierarchy increases in
granularity from the abstract meta-policies to specific detailed policies, which may be
so concrete that they directly demand or prohibit certain implementations or
mechanisms. An issue is, if abstract policies are made more specific in a parent-child
interactive relationship, this will also refer to the system or, analogously the other way
around, distinct parts of the system get their own low-level child policy which is a
refinement of a high-level parent policy for this very part. As such, for complex
system there may be large numbers of low-level child policies, and many of them may
originate from a single parent high-level policy. Thus management of these can
become quite complicated as changes of a policy regarding only a special system
module can either only be made at a high level, which would require the revalidation
of a vast amount of its child policies for every policy referring to this module.
Therefore to solve this issue, in extension to Baskerville's scheme [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ], we propose
the introduction an additional hierarchy level between high-level and low-level
policies. This new level, called mid-level policies, is intended to encompass policies
that only refer to such larger system modules.
        </p>
        <p>
          Besides the policy hierarchy considerations, for this paper we also adapt a policy
life-cycle model from Baskerville et al. [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ] for security focussed policies. The
adapted life-cycle contains for each policy the following phases:
        </p>
        <p>Specification of policy requirements: The identification and classification of
security objects and subjects are two essential requirements that have to be
encompassed by context modelling prior to the policy design and implementation, as
the meta-policies should ensure that these requirements become primary features of
the security policies. Security objects are the security relevant assets of the system,
and security subjects refers to the different entities that have a relevant security
connection to the objects. In the context model describing the objects and subjects,
also the connections between these (e.g. access levels and types) have to be specified.</p>
        <p>Policy design processes: In general, some form of meta-policies should specify the
process by which the lower-level policies are generated and enforced. For a complex
system, the usage of a hierarchy of policies ensures the required scalability. The
granularity of the different security policy levels in this hierarchy should be specified
in the design. As mentioned above, we use in this paper a hierarchical policy
approach with meta-policies, high-level, mid-level and low-level policies. The policy
design process also includes decisions on policy expression languages and policy
distribution as well as enforcement. Some policies should be enforced technically
with computer technology (i.e. using access control software), some policies should
be enforced organisationally, while some other policies should be enforced using
personnel-focused mechanisms (like training of users or raising security awareness).
Furthermore, the design of policies enforced technically should also consider the
intended expression, distribution and enforcement standards (see the remarks below).</p>
        <p>Policy implementation: How the policies are to be implemented based on
expression languages and standards should also be determined and specified using
meta-policies. The implementation also includes policy testing. Here functional
evaluations as well as investigations on potential policy conflicts have to be
performed. Nevertheless there is a usual problem that the implementation encounters:
the policies are expressed in a natural language and thus too complex. In our concept
this problem is solved by applying a manual and iterative procedure to turn them to
enforceable rules, which are defined as formalised atomic descriptions of specific
actions. More details are offered in section 3.2.</p>
        <p>
          Policy enforcement: Boyle et al. developed the Common Open Policy Service
(COPS) standard [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ], which serves well for typical policy-based systems such as
Authentication, Authorisation and Accounting (AAA) systems [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ]. Using COPS the
policies can be enforced via a three-tier-model: Policies are stored in the Policy
Repository (PR), which could be a database, a flat file, an administrative server, or a
directory server [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ]. A Policy Definition Point (PDP) retrieves the policies from PR,
parses and evaluates them and sends necessary commands to policy targets [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ],
while a Policy Enforcement Point (PEP) communicates directly with the policy
targets and gives instructions of performing the policy actions following the received
commands [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ]. For communication between PDP and PEP, a query and response
protocol is developed for exchanging policy information and decisions between them
[
          <xref ref-type="bibr" rid="ref17">17</xref>
          ]. It is designed to operate reliably and in real time with minimal overhead, thus it
provides a dedicated QoS controller for the PEP. Additionally, when necessary, Local
Policy Decision Point (LPDP) can be defined between PDP and PEPs. In this case the
PEPs take policy decisions from the LPDP for their domain, while the PDP remains
the authoritative decision point at all times. Parallel to the enforcement an auditing of
the system has to be performed where some monitoring mechanism should detect any
failed enforcement attempt or policy conflict. In this enforcement phase also the
execution of replacement or termination of policies is performed.
3
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Design of our contextualisation framework</title>
      <p>Based on the state-of-the-art presented in section 2, here we describe our framework
for contextualisation of security for digital long-term preservation. This framework
consists of four major functional blocks: context modelling, policy generation
hierarchy with its different stages, Information Package (IP) processing and control.
The context modelling block consists of two distinct parts: global (system-wide) and
local context modelling. The policy generation hierarchy is a hierarchy of stages
beginning at the top with the generation of system-wide global policies and ending in
the deviation and invocation of rules for IP processing operations. The IP processing
itself identifies the IPs (or related system data) to be processed and applies the rules as
sequences of atomic data processing operations. The control block controls the
context modelling and the policy generation hierarchy and acts as a central policy
repository as well as a central audit service for the overall system.</p>
      <p>Within the following sections we describe these functional blocks in more detail
and show how to model context, generate and implement as well as enforce security
policies based on use-cases from a data intensive, complex, security-oriented data
processing system like an archive for digital long-term preservation.
3.1</p>
      <sec id="sec-3-1">
        <title>Context modelling for complex, security-oriented data processing systems</title>
        <p>A complex data processing system usually contains multiple processing entities with
different types of relationships among the entities. Therefore the “top-down”
modelling approach is not suitable, as achieving a complete and vivid representation
as a starting point in context modelling is not feasible under these circumstances.
Instead, it is more appropriate to first extract typical tasks (workflows) from use-cases
in such systems and then gradually extend these into a fully developed context model.
As ontology based context modelling has its speciality in organising complex
structured context data, it is reasonable to apply it in the construction of the model for
such systems. The resulting ontology describes the entities in the system as well as
their relationships. The latter are expressed here in the form of policies and rules.</p>
        <p>Creation
Assembly</p>
        <p>P
r
e
In
g
e
ts</p>
        <p>Ingest</p>
        <p>
          OAIS
In digital long-term preservation the basis for context modelling is the OAIS
standard [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ]. Its functional model describes several processes of an archival system,
their tasks and their relationships as well as data items – thus providing a general
context of systems for this application scenario (see Figure 1). In these processes
typical use-cases are grouped. In the ingest data objects that should be preserved are
received from a producer and converted into the archives data format. The archival
storage stores and manages these data objects inside the archival system. The data
management provides services for the discovery, access to the metadata, and
maintaining the referential integrity between data objects. The administration process
is responsible for the operation of the archival storage, procuring and installing new
hardware and software and the organisational enforcement of the policies and
standards. The preservation planning ensures that the archival storage can fulfil its
requirements by observing the technical state-of-the-art and legal requirements and
adapting its policies with this regard. Access, as the last major process, provides
services for consumers to locate and retrieve data objects or information about them.
        </p>
        <p>
          Within the SHAMAN project Brocks et al. [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ] extended the OAIS model by
introducing an extended Information Lifecycle Model. In this the aforementioned
processes from ingest to access are seen as phases of the lifetime of a data object. The
information lifecycle model extends this by including the objects “life” before and
after its management within an archival. The phase before a digital object enters an
archival system is called “Pre-Ingest”. This is further divided into the processes of the
actual creation of the data later to be ingested and its assembly into a package
supported by the archive. The phase after a digital object leaves an archival system is
called “Post-Access” and is also divided into two processes: adoption where the
received data is unpacked, examined, transformed, displayed or in short all tasks that
are needed for repurposing the content and reuse where the content is actually
exploited. Reuse may also include the re-ingest of this object or a derivation thereof
into an archival system, leading to a real life-cycle as shown in Figure 1. Such
connection of reuse and creation is especially the case for collaborative environments.
        </p>
        <p>Ingest
Provenance Info
Copy &amp; Enrichment
Integrity Assurance
Access Restriction
Info Col ection</p>
        <p>Preservation Planning
Disaster Handling NoPnre-avveanitliaobnity
RSeeviceuwrit&amp;y PAodlaicpiteiosn ConfidMeingtriaatlioOnbjects</p>
        <p>Data Management</p>
        <p>
          Archival Storage
MAauitnhteenntaicnictye EAnfuodricteTmraeinlt
Provenance Info Operations
Maintenance Integrity Verification
Within this paper the considerations are limited on the central phase of the
Information Lifecycle Model, the archival phases described by OAIS, and security
considerations. As the original OAIS ISO standard is lacking detailed information
about security requirements, it needs to be enhanced in this regard within this paper.
Thus we analyse the archival use-cases provided by the SHAMAN research project
and extract the tasks which would have to be considered in addition to the already
existing OAIS functional entities. Thereby these extensions, which may not be
separate entities but can be incorporated into existing ones, provide better context
representation in terms of security. Figure 2 shows just these new tasks focused on
risk mitigation for the OAIS processes, whereas the tasks and functional entities of
the original OAIS model are omitted in this figure for the sake of clarity. The
interested reader may refer to the OAIS documentation [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ] for details on these
original tasks and functional entities.
        </p>
        <p>The global context model visualised on different levels of detail in Figure 1
(Information Lifecycle Model) and Figure 2 (detailed overview over the security tasks
in the OAIS processes) is then used as starting point for policy generation described
in section 3.2. Each process (Ingest, Access, etc.) has its own entity taking
responsibility of the local context modelling as well as the generation, distribution,
implementation and enforcement of policies within its own domain (scope of the
process). All entities within this domain can act as the enforcement points for policies.
3.2</p>
      </sec>
      <sec id="sec-3-2">
        <title>Use-case-driven policy generation, implementation and enforcement</title>
        <p>Based on the assumption that a “top-down” modelling approach is not suitable, which
is explained in section 3.1, it is reasonable to derive policies for complex data
processing systems from use-cases. Furthermore, to more vividly represent the
complex relationships among the entities in such systems and to implement means of
governance or orchestration a hierarchical organisation of the policies is applied.</p>
        <p>
          As mentioned in section 2.2, in this paper we use the three-level approach from
Baskerville et al. [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ] and enhance it to a four-level policy hierarchy.
        </p>
        <p>Our proposed policy generation starts on a global system level with the most
abstract types of policies – meta-policies and high-level policies. The first makes
statements about other policies and the second about general security goals and
acceptable procedures on a system-wide perspective. Thus they can either be derived
from use-cases making policy assertions and from system use-cases, respectively, or
come from the general understanding of the system or the application scenario.</p>
        <p>
          Inspired by practice of defining optional LPDPs in the COPS standard [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ], we
decide to add another layer of mid-level policies in the previous three-layer policy
model introduced in [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ], for better handling of larger complex system modules. This
reflects the fact that many use-cases do not make assertions about the system as a
whole, but about certain functionalities. Such use-cases are restricted to larger system
modules (in our case equivalent to the OAIS processes) and their domain of
functional entities. In the policy generation hierarchy these mid-level policies on the
one hand serve as a process-based filter for the use-cases of which a system may have
a large amount of, and on the other hand they serve to verify if the high-level policies
themselves make sense by not contradicting the existing use-cases (i.e. verify the
consistency between global and local context modelling).
        </p>
        <p>The mid-level policies are used to act as the basis for the generation of low-level
policies, which provide sufficient information what should be implemented as a rule
in the enforcing. In the ideal case these low-level policies should be precise enough to
directly derive rules in a formalised language from them.</p>
        <p>For the sake of clarity and for the sake of the traceability of the policies origins, a
policy derived from a higher policy should have an identifier indicating its parent
policies. If high-level policies have an identifier of the format Px (with x being an
unique identifier) their children mid-level policies should have an identifier that
includes their parent’s identifier (e.g. Px-y). As policies need to be updated or even
removed at certain times, this form of traceability eases the browsing of the
hierarchical tree structure of the policies that would be required in these cases.</p>
        <p>For highly complex systems there arise some issues for the implementation and
enforcement of policies: First, when introducing a new policy into such systems, there
could be multiple possible methods to implement it, thus it requires specific analyses
(e.g. complexity-based) to identify the optimal method. If the COPS standard for
policy management were applied in this case, these considerations would have to be
also extended to policy decisions on the selection of PEPs. Second, complex systems
are with a high probability also heterogeneous, therefore considerations have to be
included on the interoperability, distribution and orchestration of policies and policy
descriptions (for instance how to interpret between possible different policy syntaxes
used in different parts of a heterogeneous system). Third, due to the quantity and
complexity of the policies, it is necessary to develop an assurance and auditing
mechanism to make sure that all the policies are enforced properly.</p>
        <p>The policies considered here are basically descriptions in natural language of what
the preservation system does, which creates barriers for actual enforcement. Thus in
our concept, the generated policies are implemented by applying a manual and
iterative procedure which turns low-level policies into enforceable rules. The
procedure is described as follows:</p>
        <p>Create Rules: This turns low-level policies, which define what needs to be done,
into rules, which define how the policy is enforced. It analyses the statement in the
policy by utilising validation criteria that consist for the significant properties, format
validation, organisational- and domain information. Then a sequence of steps is
derived, describing specific actions. Each step should be as atomic as possible, ideally
performing one action and also verifiable, so it can be considered as one abstract rule.
Optionally a rule can comprise sub-rules if one of the steps is too complex to be
described as a single action. Therefore the output here is a sequence of abstract rules.</p>
        <p>
          Instantiate Rules: Abstract rules are not executable as they only describe actions in
natural language. Therefore it is necessary to derive executable rules from abstract
ones. Templates containing the grammar and syntax for rule-engines can be used by a
rule instantiation tool to create realisations of the abstract rules. Such tool should also
keep track of the realisation process so that it is possible to track from an executable
rule back to the abstract rule and then back to the policy. Additionally, similar to
Event-Condition-Action (ECA) rules which always have the form of if…then…else,
the executable rules are formalised as Semantic Web Rule Language (SWRL) [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ]
rules embedded in the Web Ontology Language (OWL) context representation, thus
each rule becomes an executable atomic data processing operation.
        </p>
        <p>Validate Rules: Here it is ensured by validation that the instantiated executable
rules are correct implementations of the policies. The functionality of the used
validation tools would be defined by the validation criteria, which are the adherence
to the global and local context models (developed in 3.1). After a rule passed the
validation, it is deployed with records of its deployment time and intended
deployment enforcement point in the production system and ready to be enforced.</p>
        <p>Once the policies are implemented, i.e. turned into formalised and validated rules
describing executable actions, it is easy to enforce them. The COPS standard can be
adapted to fit this case. Instead of PR, a Rule Repository (RR) would be used to store
the rules. Similar to PDP, Rule Decision Point (RDP) would retrieve the rules from
the RR, parse and evaluate them, then send rule decisions to rule targets, which can be
either devices or humans to perform the actions. Similar to PEPs, Rule Enforcement
Points (REPs) make direct communication with the rule targets and give them
instructions on performing the actions following the commands. Depending on the
complexity of the system, Local Rule Decision Point (LRDP) can share the
responsibility with RDP by feeding REP with detailed rule decisions, while RDP
remains authoritative rule point at all times.
3.3</p>
      </sec>
      <sec id="sec-3-3">
        <title>IP processing and Control</title>
        <p>In the IP processing block a system entity (here equivalent to a rule target) enforces
rules on IP from the archival system and/or system data (like search indexes, the user
database, etc.). The result of the enforcement has to be communicated by the
responsible REP to the central audit service. This central audit is part of the
functionality of the control block. Besides this audit functionality there are also
mechanisms for the storage of the policy tree (all policies are communicated to this
repository during the construction of the policy generation hierarchy) as well as the
policy conflict analysis and conflict resolve. The corresponding OAIS authority
responsible for these operations would be the task “Security Policies Review &amp;
Adaption” in the process of “Preservation Planning” (see Figure 2). It should keep
track of all the policies to ensure they operate properly, especially no policy from one
phase conflicts with those from other ones, similar to the responsibility shouldered by
policy decision points in the COPS standard.
3.4</p>
      </sec>
      <sec id="sec-3-4">
        <title>Combination of the functional blocks of the framework</title>
        <p>Control:
• Storage of the
policy tree
Policy conflict
analysis
Policy conflict
resolve
Audit-trailing</p>
        <p>use-cases
Global Context
Modelling
including the
derivation of
entities and tasks
information
commands
information &amp; policies
commands &amp; information
information Local Context Modelling
comm. CM for each of the</p>
        <p>OAIS processes
information &amp; policies
commands &amp; information
information &amp; policies
commands &amp; information
information &amp; policies
commands &amp; information
information</p>
        <p>IPs and/or system data</p>
        <p>CM for the overal system</p>
        <p>Global (meta- and
highlevel) policy generation
meta- and
high-level policies
Local (mid-level) policy
generation</p>
        <p>mid-level policies
Low-level policy
generation</p>
        <p>low-level policies
Derivation of rules</p>
        <p>rules
Invocation of rules</p>
        <p>Global preservation
planning and policy
generation
Local policy
generation
Policy
implementation
Policy enforcement /
IP processing</p>
        <p>IPs and/or syst. data
In this paper we have outlined a bottom-up context modelling approach which derives
a hierarchical policy structure from given use-cases for a long-term archiving system.
An existing concept from literature has been extended accordingly into a complete
contextualisation framework to meet the (security) requirements of a digital long-term
preservation system.</p>
        <p>However, there exist several limitations for our approach that have to be addressed
in future work: First, it is hard to evaluate whether the constructed context model (as
basis for the policy generation process) is too specific with unnecessary redundancy
or too abstract with lack of necessary details, as currently no metrics for the
preciseness of such models exist. Furthermore, it is difficult to investigate how
vividly the lower level policies reflect the intentions of the high level policies from
which they derived, yet the biases (or even conflicts) between could lead to problems
in their enforcement.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>Acknowledgement</title>
      <p>The work in this paper has been supported in part by the European Commission
through the FP7 ICT Programme under Contract FP7-ICT-216736 SHAMAN. The
information in this document is provided as is, and no guarantee or warranty is given
or implied that the information is fit for any particular purpose. The user thereof uses
the information at its sole risk and liability.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Consultative</surname>
          </string-name>
          <article-title>Committee for Space Data Systems (CCSDS): Reference Model for an Open Archival Information System (OAIS). Recommendation for Space Data System Standards</article-title>
          ,
          <source>CCSDS 650.0-B-1</source>
          ,
          <string-name>
            <given-names>Blue</given-names>
            <surname>Book</surname>
          </string-name>
          (ISO 14721:
          <year>2003</year>
          ),
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>M.</given-names>
            <surname>Schott</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Kraetzer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Dittmann</surname>
          </string-name>
          ,
          <string-name>
            <surname>C.</surname>
          </string-name>
          <article-title>Vielhauer: Extending the Clark-Wilson Security Model for Digital Long-Term Preservation Use-cases</article-title>
          ,
          <source>Proc. of Multimedia on Mobile Devices</source>
          ,
          <year>2010</year>
          , SPIE Electronic Imaging Conference 7542,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>D. D. Clark</surname>
            ,
            <given-names>D. R.</given-names>
          </string-name>
          <string-name>
            <surname>Wilson</surname>
          </string-name>
          :
          <article-title>A Comparison of Commercial and Military Computer Security Policies</article-title>
          ,
          <source>IEEE Symposium on Security and Privacy</source>
          ,
          <year>1987</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <given-names>M.</given-names>
            <surname>Schott</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Kraetzer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Specht</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Dittmann</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Vielhauer</surname>
          </string-name>
          , Ensuring Integrity and
          <article-title>Authenticity for Images in Digital Long-Term Preservation</article-title>
          ,
          <source>Proc. of Optics</source>
          ,
          <article-title>Photonics and Digital Technologies for Multimedia Applications</article-title>
          , SPIE Photonics Europe,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <given-names>H.</given-names>
            <surname>Brocks</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Kranstedt</surname>
          </string-name>
          , G. Jäschke,
          <string-name>
            <surname>M.</surname>
          </string-name>
          <article-title>Hemmje: Modeling Context for Digital Preservation</article-title>
          ,
          <source>Studies in Computational Intelligence</source>
          , vol.
          <volume>260</volume>
          , pp.
          <fpage>197</fpage>
          -
          <lpage>226</lpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <given-names>R.</given-names>
            <surname>Bhatti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Bertino</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Ghafoor</surname>
          </string-name>
          ,
          <article-title>A Trust-based Context-Aware Access Control Model for Web-Services</article-title>
          ,
          <source>Proc. of the IEEE International Conferences on Web Services</source>
          ,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <given-names>W.</given-names>
            <surname>Tolone</surname>
          </string-name>
          , G. Ahn,
          <string-name>
            <given-names>T.</given-names>
            <surname>Pai</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Hong</surname>
          </string-name>
          ,
          <source>Access Control in Collaborative Systems, ACM Computing Survays</source>
          , Vol.
          <volume>37</volume>
          ,
          <year>March 2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <given-names>M.</given-names>
            <surname>Covington</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Long</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Srinivasan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Dey</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Ahamad</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. D.</given-names>
            <surname>Abowd</surname>
          </string-name>
          ,
          <article-title>Securing Context-Aware Applications Using Environment Roles</article-title>
          ,
          <source>ACM Symposium on Access Control Model and Technology</source>
          ,
          <string-name>
            <surname>ACM</surname>
          </string-name>
          , Chantilly,
          <string-name>
            <surname>VA</surname>
          </string-name>
          , USA,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <given-names>C.</given-names>
            <surname>Kraetzer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Qian</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Schott</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Dittmann</surname>
          </string-name>
          ,
          <article-title>A Context Model for Microphone Forensics and its Application in Evaluations</article-title>
          ,
          <source>Proc. of Media Watermarking</source>
          , Security and
          <string-name>
            <surname>Forensics</surname>
            <given-names>XIII</given-names>
          </string-name>
          , IS&amp;T/SPIE Electronic Imaging Conference7880, San Francisco, CA, USA,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>R. J. Anderson</surname>
            ,
            <given-names>A Security</given-names>
          </string-name>
          <string-name>
            <surname>Polity</surname>
          </string-name>
          <article-title>Model for Clinical Information Systems</article-title>
          ,
          <source>Proc. of IEEE Symposium on Security and Privacy</source>
          ,
          <year>1996</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>C. Bettini</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          <string-name>
            <surname>Brdiczka</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          <string-name>
            <surname>Henricksen</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Indulska</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          <string-name>
            <surname>Nicklas</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Ranganathan</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          <string-name>
            <surname>Riboni</surname>
          </string-name>
          ,
          <article-title>A Survey of Context Modelling and Reasoning Techniques, Pervasive</article-title>
          and
          <string-name>
            <given-names>Mobile</given-names>
            <surname>Computing</surname>
          </string-name>
          , Elsevier,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <given-names>G.</given-names>
            <surname>Klyne</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Reynolds</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Woodrow</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Ohto</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Hjelm</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. H.</given-names>
            <surname>Butler</surname>
          </string-name>
          , L. Tran, Composite Capability/Preference Profiles (CC/PP):
          <source>Structure and Vocabularies 1</source>
          .0,
          <string-name>
            <given-names>W3C</given-names>
            <surname>Recommendations</surname>
          </string-name>
          ,
          <year>W3C</year>
          ,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <given-names>T.</given-names>
            <surname>Strang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Linnhoff-Popien</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A Context</given-names>
            <surname>Modeling</surname>
          </string-name>
          <string-name>
            <surname>Survey</surname>
          </string-name>
          ,
          <source>Proc. of the First International Workshop on Advanced Context Modelling, Reasoning and Management</source>
          , in conjunction with
          <source>UbiComp</source>
          <year>2004</year>
          , Nottingham, England,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <given-names>R.</given-names>
            <surname>Baskerville</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Siponen</surname>
          </string-name>
          ,
          <article-title>An Information Security Meta-policy for Emergent Organizations</article-title>
          ,
          <source>Logistics Information Management</source>
          , Volume
          <volume>15</volume>
          , Number 5/6,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>J. Boyle</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          <string-name>
            <surname>Cohen</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Herzog</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          <string-name>
            <surname>Rajan</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Sastry</surname>
          </string-name>
          ,
          <string-name>
            <surname>The COPS (Common Open Policy Service) Protocol</surname>
          </string-name>
          ,
          <fpage>RFC2748</fpage>
          ,
          <year>2000</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>C. Rensing</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Karsten</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          <string-name>
            <surname>Stiller</surname>
          </string-name>
          ,
          <article-title>AAA: A Survey and a Policy-Based Architecture and Framework</article-title>
          , IEEE Network, Vol.
          <volume>16</volume>
          ,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <given-names>R.</given-names>
            <surname>Rajan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Verma</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kamat</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Felstaine</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Herzog</surname>
          </string-name>
          ,
          <article-title>A Policy Framework for Integrated and Differentiated Services in the Internet</article-title>
          ,
          <source>IEEE Network</source>
          , Vol.
          <volume>13</volume>
          ,
          <year>1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <given-names>K.</given-names>
            <surname>Yang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Galis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Todd</surname>
          </string-name>
          ,
          <article-title>Policy-Based Active Grid Management Architecture</article-title>
          ,
          <source>Proc. of 10th IEEE International Conference on Networks</source>
          ,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19. I. Horrocks,
          <string-name>
            <given-names>P. F.</given-names>
            <surname>Petal-Schneider</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Boley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Tabet</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Grosof</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.</surname>
          </string-name>
          <article-title>Dean, SWRL: A Semantic Web Rule Language Combining OWL and RuleML</article-title>
          ,
          <source>Member submission 21 May</source>
          <year>2004</year>
          , W3C,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <surname>J. Fridrich</surname>
          </string-name>
          ,
          <article-title>Digital Image Forensic Using Sensor Noise</article-title>
          ,
          <source>IEEE Signal Processing Magazine</source>
          , vol.
          <volume>26</volume>
          , no.
          <issue>2</issue>
          ,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>21. SHAMAN website: http://www.shaman-ip.eu</mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>