Access control: principles and solutions

  • Authors:
  • Sabrina De Capitani di Vimercati;Stefano Paraboschi;Pierangela Samarati

  • Affiliations:
  • Dipartimento di Tecnologie dell'Informazione, Università di Milano, Via Bramante 65, 26013 Crema, Italy;Dipartimento di Ingegneria, Università di Bergamo, Via Marconi 5, 24044 Dalmine, Italy;Dipartimento di Tecnologie dell'Informazione, Università di Milano, Via Bramante 65, 26013 Crema, Italy

  • Venue:
  • Software—Practice & Experience - Special issue: Security software
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

Access control is the process of mediating every request to resources and data maintained by a system and determining whether the request should be granted or denied. The variety and complexity of the protection requirements that may need to be imposed makes access control a far from trivial process. Expressiveness and flexibility are top requisites for an access control system together with, and usually in conflict with, simplicity and efficiency. In this paper, we discuss the main desiderata for access control systems and illustrate the main characteristics of access control solutions in some of the most popular existing systems.