Abstract
The per-method access control lists of standard middleware technologies allow only simple forms of access control to be expressed and enforced. Research systems based on capabilities provide a more secure mechanism but also fail to support more flexible security constraints such as parameter restrictions, logging and state-dependent access. They also fail to enforce a strict need-to-know view of a persistent object for each user. In this paper we present the concept of bracket capabilities as a new, simple security mechanism which fulfils these requirements. We discuss the reasons for integrating bracketing and view types at a fundamental level of the security mechanism. We demonstrate the use of the mechanism in a simple Ecommerce environment to provide secure electronic cheques and describe a prototype implementation of the mechanism in middleware for secure, distributed Java applications.
| Original language | English |
|---|---|
| Title of host publication | Computer Science 2002: Proceedings of the Twenty-Fifth Australasian Computer Science Conference (ACSC2002) |
| Editors | Michael J Oudshoorn |
| Place of Publication | Sydney, Australia |
| Publisher | Australian Computer Society (ACS) |
| Pages | 51-58 |
| Volume | 7 |
| ISBN (Print) | 0909925828 |
| Publication status | Published - 2002 |
| Event | ACSC 2002: Twenty-Fifth Australasian Computer Science Conference - Melbourne, Australia Duration: 28 Jan 2002 → 1 Feb 2002 |
Conference
| Conference | ACSC 2002: Twenty-Fifth Australasian Computer Science Conference |
|---|---|
| City | Melbourne, Australia |
| Period | 28/01/02 → 1/02/02 |
Keywords
- Computer Software
Fingerprint
Dive into the research topics of 'Bracket Capabilities for Distributed Systems Security'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver