|
ABSTRACT
In the context of a capability-based protection system, the term “transfer” is used (here) to refer to the situation where a user receives information when he does not initially have a direct “right” to it. Two transfer methods are identified: de jure transfer refers to the case when the user acquires the direct authority to read the information; de facto transfer refers to the case when the user acquires the information (usually in the form of a copy and with the assistance of others), without necessarily being able to get the direct authority to read the information. The Take-Grant Protection Model, which already models de jure transfers, is extended with four rewriting rules to model de facto transfer. The configurations under which de facto transfer can arise are characterized. Considerable motivational discussion is included.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
G. S. Graham and P. J. Denning. Protection - principles and practices. Proceedings of SJCC, pp.417-429, 1972.
|
| |
2
|
|
| |
3
|
The Concise Oxford English Dictionary. Oxford University Press, Sixth Edition, 1976.
|
 |
4
|
|
 |
5
|
|
| |
6
|
A. K. Jones, R. J. Lipton and L. Snyder. A linear time algorithm for deciding security. Proceedings of the 17th Annual Symposium on Foundations of Computer Science, 1976.
|
| |
7
|
L. Snyder. Formal Models of Capability-Based Protection Systems. Yale Department of Computer Science Technical Report, #151, 1978.
|
| |
8
|
R. W. Fabry, private communication.
|
| |
9
|
W. L. Ruzzo, private communication.
|
| |
10
|
Matt Bishop and Lawrence Snyder. The Transfer of Information and Authority in a Protection System. Yale Department of Computer Science Technical Report, #166, 1979.
|
 |
11
|
|
| |
12
|
Anita K. Jones and Richard J. Lipton. The enforcement of security policies for computation. JCSS 17(1):35-55 (January, 1978).
|
CITED BY 10
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Prasad Naldurg , Stefan Schwoon , Sriram Rajamani , John Lambert, NETRA:: seeing through access control, Proceedings of the fourth ACM workshop on Formal methods in security, p.55-66, November 03-03, 2006, Alexandria, Virginia, USA
|
|
|
Philip Derrin , Kevin Elphinstone , Gerwin Klein , David Cock , Manuel M. T. Chakravarty, Running the manual: an approach to high-assurance microkernel development, Proceedings of the 2006 ACM SIGPLAN workshop on Haskell, September 17-17, 2006, Portland, Oregon, USA
|
|
|
|
|