Context-aware access control and the GEO-RBAC framework

Geo-RBAC (Geographical Role-based Access Control) is a location-aware access control system developed on top of standard RBAC (Role Based Access Control). Geo-RBAC supports the specification of spatial constraints relating the position of the requesting subject to bounded regions. Key concepts:

  • Spatial role: a role which is effective in a bounded region
  • Role schema: a template for semantically homogeneous spatial roles
  • Logical position: geographical place at policy-dependent granularity
  • Spatial roles and roles schemas hierarchy
  • Separation of duty constraints on spatial roles and spatial role schemas
  • Spatial domain: spatially-bounded policy administration context


