A Type System for Discretionary Access Control - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Article Dans Une Revue Mathematical Structures in Computer Science Année : 2009

A Type System for Discretionary Access Control

Résumé

Discretionary Access Control (DAC) systems provide powerful resource management mechanisms based on the selective distribution of capabilities to selected classes of principals. We study a type-based theory of DAC models for a process calculus that extends Cardelli, Ghelli and Gordon's pi-calculus with groups (Cardelli et al. 2005). In our theory, groups play the role of principals and form the unit of abstraction for our access control policies, and types allow the specification of fine-grained access control policies to govern the transmission of names, bound the (iterated) re-transmission of capabilities and predicate their use on the inability to pass them to third parties. The type system relies on subtyping to achieve a selective distribution of capabilities to the groups that control the communication channels. We show that the typing and subtyping relationships of the calculus are decidable.
Fichier non déposé

Dates et versions

inria-00535981 , version 1 (14-11-2010)

Identifiants

  • HAL Id : inria-00535981 , version 1

Citer

Michele Bugliesi, Dario Colazzo, Silvia Crafa, Damiano Macedonio. A Type System for Discretionary Access Control. Mathematical Structures in Computer Science, 2009. ⟨inria-00535981⟩
70 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More