Discretionary capability confinement

  • Authors:
  • Philip W. L. Fong

  • Affiliations:
  • University of Regina, Department of Computer Science, Regina, SK, Canada

  • Venue:
  • International Journal of Information Security
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Motivated by the need of application-level access control in dynamically extensible systems, this work proposes a static annotation system for modeling capabilities in a Java-like programming language. Addressing a common critique of capability systems, the proposed annotation system can provably enforce capability confinement. This confinement guarantee is leveraged to model a strong form of separation of duty known as hereditary mutual suspicion. The annotation system has been fully implemented in a standard Java Virtual Machine.