1984 IEEE Symposium on Security and Privacy (1984)
Oakland, CA
Apr. 29, 1984 to May 2, 1984
ISSN: 1540-7993
ISBN: 0-8186-0532-4
pp: 2
Paul A. Karger , Digital Equipment Corporation
Andrew J. Herbert , University of Cambridge
This paper describes a protection system that supports the confinement of access as required by non-discretionary access control models such as the Bell and LaPadula lattice model. The approach is to use capability-based protection at the lowest level for implementing confined domains, in support of access control lists for expressing security policies outside the security kernel. The implementation of such a system in the context of hardware support for capabilities is discussed.
Access control, Lattices, Software, Permission, Computer architecture, Trajectory

