Generalized access control of synchronous communication

  • Authors:
  • Constantin Serban;Naftaly Minsky

  • Affiliations:
  • Computer Science Department, Rutgers University, Piscataway, NJ;Computer Science Department, Rutgers University, Piscataway, NJ

  • Venue:
  • Middleware'06 Proceedings of the 7th ACM/IFIP/USENIX international conference on Middleware
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

The security of modern networked applications, such as the information infrastructure of medical institutions or commercial enterprises, requires increasingly sophisticated access control (AC) that can support global, enterprise-wide policies that are sensitive to the history of interaction. The Law-Governed Interaction (LGI) mechanism supports such policies, but so far only for asynchronous message passing communication. This paper extends LGI to synchronous communication, thus providing advanced control over this important and popular mode of communication. Among the novel characteristics of this control are: the regulation of both the request and the reply, separately, but in a coordinated manner; regulated timeout capability provided to clients, in a manner that takes into account the concerns of their server; and enforcement on both the client and server sides.