|
ABSTRACT
We investigate how protection requirements may be specified and implemented using the imperative, availability and coercion paradigms. Conventional protection mechanisms generally follow the imperative paradigm, requiring explicit and often centralized control over the sequencing and the mediation of security critical operations. This paper illustrates how casting protection in the availability and/or coercion styles provides the basis for more flexible and potentially distributed control over the sequencing and mediation of these operations.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
ARVIND, AND GOSTELOW, K. P. A computer capable of exchanging processors for time. Information Processing 77 Proceedings of IFIP Congress 77 Pages 849-853, Toronto, Canada, August 1977.
|
| |
2
|
BLAZE, M., ET AL. The keynote trust-management system version 2. Internet Request For Comments 2704.
|
| |
3
|
BREWER, D., AND NASH, M. The Chinese Wall security policy. In Proceedings of the 1989 IEEE Symposium on Security and Privacy (May 1989), IEEE Computer Society Press, pp. 206-214.
|
 |
4
|
|
| |
5
|
FOLEY, S., QUILLINAN, T., MORRISON, J., POWER, D., AND KENNEDY, J. Exploiting KeyNote in Web-Com: Architecture neutral glue for trust management. In Fifth Nordic Workshop on Secure IT Systems (Reyk-javik, Iceland, Oct 2001).
|
| |
6
|
HARARY, F., NORMAN, R., AND CARTWRIGHT, D. Structural models: An introduction to the theory of directed graphs. John Wiley and Sons,1969.
|
 |
7
|
|
| |
8
|
MORRISON, J. Condensed Graphs: Unifying Availability-Driven, Coercion-Driven and Control-Driven Computing. PhD thesis, Eindhoven, 1996.
|
| |
9
|
|
| |
10
|
MORRISON, J., POWER, D., AND KENNEDY, J. A Condensed Graphs Engine to Drive Metacomputing. Proceedings of the international conference on parallel and distributed processing techniques and applications (PDPTA '99), Las Vagas, Nevada, June 28 - July1, 1999.
|
| |
11
|
MORRISON, J., AND REM, M. Managing and exploiting speculative computations in a flow driven, graph reduction machine. proceedings of PDPTA'99: Las Vegas, USA. June 28-July 1, 1999.
|
| |
12
|
NASH, M., AND POLAND, K. Some conundrums concerning separation of duty. In Proceedings of the Symposium on Security and Privacy (Oakland, CA, May 1990), IEEE Computer Society Press, pp. 201-207.
|
| |
13
|
R. D. BLUMOFE, P. L. Adaptive and reliable parallel computing on networks of workstations. Proceedings of the USENIX 1997 Annual Technical Symposium (January 1997).
|
 |
14
|
|
|