Ensuring integrity by adding obligations to privileges

  • Authors:
  • Naftaly H. Minsky;Abe D. Lockman

  • Affiliations:
  • Department of Computer Science, Rutgers University, New Brunswick, N.J;Horizon Information Systems, 1050 George Street, #6-F New Brunswick, N.J

  • Venue:
  • ICSE '85 Proceedings of the 8th international conference on Software engineering
  • Year:
  • 1985

Quantified Score

Hi-index 0.00

Visualization

Abstract

Conventional authorization mechanisms provide actors with permissions to act, without the actor ever incurring any obligations as a result of executing the permitted action. There exist, however, many situations where system integrity requires that certain actions always be followed by others, within some reasonable time frame. We propose an extension to conventional authorization which allows the explicit association of obligations with permissions, and enforces them. We demonstrate that the extended mechanism can be used to support and enforce several general types of control policies and integrity constraints which are otherwise difficult or impossible to support.