1997 IEEE Symposium on Security and Privacy An Authorization Scheme For Distributed Object Systems Oakland, CA May 04-May 07 ISBN: 0-8186-7828-3
This paper addresses the problem of distributed object system protection. A new authorization scheme is presented and described. It is based on the collaboration between a central authorization server and security kernels located on each site of the system. A novel approach to access rights management for such an architecture is detailed: it is based on a new kind of access rights and a new scheme of privilege delegation. This authorization scheme can be adapted to various security policies, including multilevel policies such as Bell-LaPadula. An extension of the Bell-LaPadula model to distributed object systems is presented and its implementation using the authorization scheme is described.
Index Terms:
authorization, protection, access rights, delegation, object model, multilevel security policy
Citation:
V. Nicomette, Y. Deswarte, "An Authorization Scheme For Distributed Object Systems," sp, pp.0021, 1997 IEEE Symposium on Security and Privacy, 1997 Usage of this product signifies your acceptance of the Terms of Use. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||