Authorization in Distributed Systems: A Formal Approach

  • Authors:
  • Affiliations:
  • Venue:
  • SP '92 Proceedings of the 1992 IEEE Symposium on Security and Privacy
  • Year:
  • 1992

Quantified Score

Hi-index 0.00

Visualization

Abstract

In most systems, authorization is specified using some low-level system-specific mechanisms,e.g. protection bits, capabilities and access control lists. We argue that authorization is an independent semantic concept that must be separated from implementation mechanismsand given a precise semantics. We propose a logical approach to representing and evaluating authorization. Specifically, we introduce a language for specifying policy bases. A policy base encodes a set of authorization requirements and is given a precise semantics based upon a formal notion of authorization policy. The semantics is computable, thus providing a basis for authorization evaluation. We also introduce two composition operators for policy bases, which are appropriate for modeling distributed systems with multiple administrative domains.