DISCRETIONARY ACCESS-CONTROL BY MEANS OF USAGE CONDITIONS

被引:1
|
作者
BORN, E
STIEGLER, H
机构
[1] Siemens Nixdorf Informationssysteme AG, D-81739 München
关键词
ACCESS CONTROL INFORMATION; ACCESS RELATION ATTRIBUTES; DISCRETIONARY ACCESS CONTROL; PERMISSION SETS; USAGE CONDITIONS; USER INTERFACE;
D O I
10.1016/0167-4048(94)90037-X
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A data processing environment allows users to create data objects of very different types. As a part of the management of these objects, the data processing system must support user-defined access control. In this paper we propose a general concept and user interface for user-defined access control and discuss a number of applications. The concept regards access control information as valuable information in its own right and consequently places this information, nowadays mostly specified within and as an integral part of meta-information either of objects or subjects, in objects of its own, called usage conditions. Each of these objects contains access control information corresponding to a task of the real world and formulated with general attributes. Access control for an object is implemented by references to appropriate usage conditions. Access to the object is granted if granted by at least one usage condition. Thus, by setting such references in an m-to-n manner, a restricted set of usage conditions is sufficient to implement even complex access control conditions.
引用
收藏
页码:437 / 450
页数:14
相关论文
共 50 条