| A temporal authorization model |
| Full text |
Pdf
(1.06 MB)
|
| Source
|
Conference on Computer and Communications Security
archive
Proceedings of the 2nd ACM Conference on Computer and communications security
table of contents
Fairfax, Virginia, United States
Pages: 126 - 135
Year of Publication: 1994
ISBN:0-89791-732-4
|
|
Authors
|
|
Elisa Bertino
|
Dipartimento di Scienze dell'Informazione, Università di Milano, via Comelico 39/41 Milano 20135, Italy
|
|
Claudio Bettini
|
Dipartimento di Scienze dell'Informazione, Università di Milano, via Comelico 39/41 Milano 20135, Italy
|
|
Pierangela Samarati
|
Dipartimento di Scienze dell'Informazione, Università di Milano, via Comelico 39/41 Milano 20135, Italy
|
|
| Sponsor |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 10, Downloads (12 Months): 39, Citation Count: 5
|
|
|
ABSTRACT
This paper presents a discretionary access control model in which authorizations contain temporal information. This information can be used to specify temporal intervals of validity for authorizations and temporal dependencies among authorizations. A formal definition of those concepts is presented in the paper, in terms of their interpretation in first order logic. We characterize sets of temporal dependencies that can lead to undesirable states of the authorization system and we sketch an algorithm for their detection. Finally, operations to add, remove, or modify authorizations and temporal dependencies are described.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
|
| |
2
|
|
| |
3
|
|
| |
4
|
|
| |
5
|
E. Bertino and P. Samarati. Research issues in discretionary authorization for object bases. In B. Thuraisingham, R. Sandhu, and T.Y. Lin, editors, Security for object-oriented systems. Springer- Verlag, London, 1994.
|
 |
6
|
Elisa Bertino , Pierangela Samarati , Sushil Jajodia, Authorizations in relational database management systems, Proceedings of the 1st ACM conference on Computer and communications security, p.130-139, November 03-05, 1993, Fairfax, Virginia, United States
[doi> 10.1145/168588.168605]
|
 |
7
|
|
| |
8
|
D. D. Clark and D. R. Wilson. A comparison of commercial and military computer security policies. In Proe. IEEE Symposium on Security and Privacy, pages 184-194, Oakland, California, April 1987.
|
| |
9
|
|
| |
10
|
|
| |
11
|
E. B. Fernandez, E. Gudes, and H. Song. A security model for object-oriented databases. In Proc. IEEE Symposium on Security and Privacy, pages 110- 115, Oakland, California, May 1989.
|
 |
12
|
|
| |
13
|
S. J ajodia and B. Kogan. Integrating an objectoriented data model with multilevel security. Proc. IEEE Symposium on Security and Privacy, Oakland, California, pages 76-85, May 1990.
|
| |
14
|
W. T. Maimone and I. B. Greenberg. Single-level multiversion schedulers for multilevel secure database systems. In Proc. 6th Annual Computer Security Applications Conf., pages 137-147, Tucson, Arizona, December 1990.
|
 |
15
|
|
| |
16
|
R.S. Sandhu. Separation of duties in computerized information systems. In S. J ajodia and C.E. Landwehr, editors, Database Security, IV: Status and Prospects, pages 179-189. North-IIolland, Amsterdam, 1991.
|
| |
17
|
|
| |
18
|
|
| |
19
|
D. L. Spooner. The impact of inheritance on security in object-oriented database systems. In C.E. Landwehr, editor, Database Security, II: Status and Prospects, pages 141-160. North-Holland, Amsterdam, 1989.
|
| |
20
|
Gerhard Steinke , Matthias Jarke, Support for security modeling in information systems design, Results of the Sixth Working Conference of IFIP Working Group 11.3 on Database Security on Database security, VI : status and prospects: status and prospects, p.125-141, January 1993, Simon Fraser Univ., Vancouver, British Columbia, Canada
|
| |
21
|
R.K. Thomas and R.S. Sandhu. Discretionary access control in object-oriented databases: Issues and research directions. In Proc. 16th National Computer Security Conference, pages 63-74, Baltimore, MD, Sept. 1993.
|
 |
22
|
|
| |
23
|
Johan van Benthem. Temporal logic. In D. Gabbay, C. I-logger, and J. Robinson, editors, Handbook of logic in artificial intelligence and logic programming, volume 3. Oxford University Press, 1991.
|
| |
24
|
T.Y.C. Woo and S.S. Lam. Authorizations in distributed systems: A new approach. Journal of Computer Security, 2(2 & 3):107-136, 1993.
|
CITED BY 5
|
Xinwen Zhang , Jaehong Park , Francesco Parisi-Presicce , Ravi Sandhu, A logical specification for usage control, Proceedings of the ninth ACM symposium on Access control models and technologies, June 02-04, 2004, Yorktown Heights, New York, USA
|
|
|
|
|
|
|
|
|
|
|
Peer to Peer - Readers of this Article have also read:
-
Data structures for quadtree approximation and compression
Communications of the ACM
28, 9
Hanan Samet
-
A hierarchical single-key-lock access control using the Chinese remainder theorem
Proceedings of the 1992 ACM/SIGAPP Symposium on Applied computing
Kim S. Lee
, Huizhu Lu
, D. D. Fisher
-
An intelligent component database for behavioral synthesis
Proceedings of the 27th ACM/IEEE Design Automation Conference on
Gwo-Dong Chen
, Daniel D. Gajski
-
The GemStone object database management system
Communications of the ACM
34, 10
Paul Butterworth
, Allen Otis
, Jacob Stein
-
Putting innovation to work: adoption strategies for multimedia communication systems
Communications of the ACM
34, 12
Ellen Francik
, Susan Ehrlich Rudman
, Donna Cooper
, Stephen Levine
|