DocumentCode :
3141720
Title :
A distributed implementation of the extended schematic protection model
Author :
Ammann, Paul ; Sandhu, Ravi S. ; Suri, Gurpreet S.
Author_Institution :
Dept. of Inf. & Software Syst. Eng., George Mason Univ., Fairfax, VA, USA
fYear :
1991
fDate :
2-6 Dec 1991
Firstpage :
152
Lastpage :
164
Abstract :
Protection models provide a formalism for specifying control over access to information and other resources in a multi-user computer system. One such model, the extended schematic protection model (ESPM) has expressive power equivalent to the monotonic access matrix model of Harrison, Ruzzo, and Ullman (1976). Yet ESPM retains tractable safety analysis for many cases of practical interest. Thus ESPM is a very general model, and it is of interest whether ESPM can be implemented in a reasonable manner. The authors outline a distributed implementation for ESPM. The implementation is capability-based, with an architecture where servers act as mediators to all subject and object access. Capabilities are made nontransferable by burying the identity of subjects in them, and unforgeable by using a public key encryption algorithm. Timestamps and public keys are used as mechanisms for revocation
Keywords :
multiprogramming; security of data; expressive power; extended schematic protection model; mediators; multi-user computer system; public key encryption algorithm; servers; tractable safety analysis; Access control; Information security; Information systems; Power engineering and energy; Power system modeling; Power system protection; Public key; Safety; Scanning probe microscopy; Software systems;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Security Applications Conference, 1991. Proceedings., Seventh Annual
Conference_Location :
San Antonio, TX
Print_ISBN :
0-8186-2280-6
Type :
conf
DOI :
10.1109/CSAC.1991.213009
Filename :
213009
Link To Document :
بازگشت