DocumentCode
2217408
Title
Access control for a modular, extensible storage service
Author
Bacon, Jean ; Hayton, Richard ; Lo, Sai Lai ; Moody, Ken
Author_Institution
Comput. Lab., Cambridge Univ., UK
fYear
1994
fDate
27-28 Jun 1994
Firstpage
108
Lastpage
114
Abstract
We have designed and built a modular and extensible multi service storage architecture (MSSA) which allows evolution from, and compatibility with, traditional applications. The MSSA comprises a two-level hierarchy of storage servers with value-adding service layers above them. We present the access control mechanism of the MSSA. Access control lists (ACLs) are used to allow fine grained expression of policy together with capabilities for efficient runtime access after a once-off ACL check. Our capabilities are principal-specific and transient and their design ensures that access to objects is via the correct service hierarchy; for example, a directory object may only be manipulated via a directory service. The implementation of this protection is stateless at the servers above the storage service. The scheme also provides a convenient means to delegate rights for an object, temporarily, to an unprivileged server, for example a print-server. The fact that our capabilities are short-lived alleviates the requirement for selective revocation and crash recovery. We report on experiences with a prototype implementation of the scheme and suggest some optimisations
Keywords
access control; file servers; memory architecture; multimedia systems; storage management; MSSA; access control lists; access control mechanism; crash recovery; extensible multi service storage architecture; fine grained expression; modular extensible storage service; once-off ACL check; principal-specific; print-server; prototype implementation; runtime access; selective revocation; service hierarchy; storage servers; two-level hierarchy; unprivileged server; value-adding service layers; Access control; Application software; Auditory displays; Authentication; Authorization; Computer architecture; File servers; Laboratories; Protection; Prototypes;
fLanguage
English
Publisher
ieee
Conference_Titel
Distributed and Networked Environments, 1994. Proceedings., First International Workshop on Services in
Conference_Location
Prague
Print_ISBN
0-8186-5835-5
Type
conf
DOI
10.1109/SDNE.1994.337771
Filename
337771
Link To Document