Decentralized administration for a temporal access control model

被引:1
作者
Bertino, E
Bettini, C
Ferrari, E
Samarati, P
机构
[1] Dipto. di Scienze dell'Informazione, Università di Milano, Milano
关键词
database management; database security; temporal authorization; authorization administration; access control;
D O I
10.1016/S0306-4379(97)00013-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper we present a temporal access control model that provides for decentralized administration of authorizations. Each access authorization, negative or positive, is associated with a time interval limiting its validity. When the interval expires, the authorization is automatically revoked. The model also permits the specification of rules, based on four different temporal operators, to derive additional authorizations from the presence or absence of other authorizations. Users creating objects can retain complete control over their objects or delegate other users the privilege of administering accesses on the objects. Delegation can also be selectively enforced with reference to specific access modes or time intervals. The resulting model provides a high degree of flexibility and allows to express several protection requirements which cannot be expressed in traditional access control models. (C) 1997 Elsevier Science Ltd.
引用
收藏
页码:223 / 248
页数:26
相关论文
共 20 条
[1]   A CALCULUS FOR ACCESS-CONTROL IN DISTRIBUTED SYSTEMS [J].
ABADI, M ;
BURROWS, M ;
LAMPSON, B ;
PLOTKIN, G .
ACM TRANSACTIONS ON PROGRAMMING LANGUAGES AND SYSTEMS, 1993, 15 (04) :706-734
[2]   A temporal access control mechanism for database systems [J].
Bertino, E ;
Bettini, C ;
Ferrari, E ;
Samarati, P .
IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 1996, 8 (01) :67-80
[3]  
Bertino E, 1996, PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON VERY LARGE DATA BASES, P472
[4]  
BERTINO E, 1996, P 1996 IEEE S SEC PR
[5]  
BOBROWSKI S, 1993, DBMS, P44
[6]  
CASTANO S, 1995, DATABASE SECURITY
[7]  
FAGIN R, 1976, ACM T DATABASE SYST, V3, P310
[8]  
FERRARI E, 1996, P POST SIGMOD WORKSH, P34
[9]  
FINE T, 1994, DEV POLICY NEUTRAL C
[10]  
Griffiths P. P., 1976, ACM Transactions on Database Systems, V1, P242, DOI 10.1145/320473.320482