An Authorization Scheme For Distributed Object Systems

  • Authors:
  • V. Nicomette;Y. Deswarte

  • Affiliations:
  • -;-

  • Venue:
  • SP '97 Proceedings of the 1997 IEEE Symposium on Security and Privacy
  • Year:
  • 1997

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper addresses the problem of distributed object system protection. A new authorization scheme is presented and described. It is based on the collaboration between a central authorization server and security kernels located on each site of the system. A novel approach to access rights management for such an architecture is detailed: it is based on a new kind of access rights and a new scheme of privilege delegation. This authorization scheme can be adapted to various security policies, including multilevel policies such as Bell-LaPadula. An extension of the Bell-LaPadula model to distributed object systems is presented and its implementation using the authorization scheme is described.