Skip to main navigation Skip to search Skip to main content

Bracket Capabilities for Distributed Systems Security

Mark Peter Evered

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The per-method access control lists of standard middleware technologies allow only simple forms of access control to be expressed and enforced. Research systems based on capabilities provide a more secure mechanism but also fail to support more flexible security constraints such as parameter restrictions, logging and state-dependent access. They also fail to enforce a strict need-to-know view of a persistent object for each user. In this paper we present the concept of bracket capabilities as a new, simple security mechanism which fulfils these requirements. We discuss the reasons for integrating bracketing and view types at a fundamental level of the security mechanism. We demonstrate the use of the mechanism in a simple Ecommerce environment to provide secure electronic cheques and describe a prototype implementation of the mechanism in middleware for secure, distributed Java applications.
Original languageEnglish
Title of host publicationComputer Science 2002: Proceedings of the Twenty-Fifth Australasian Computer Science Conference (ACSC2002)
EditorsMichael J Oudshoorn
Place of PublicationSydney, Australia
PublisherAustralian Computer Society (ACS)
Pages51-58
Volume7
ISBN (Print)0909925828
Publication statusPublished - 2002
EventACSC 2002: Twenty-Fifth Australasian Computer Science Conference - Melbourne, Australia
Duration: 28 Jan 20021 Feb 2002

Conference

ConferenceACSC 2002: Twenty-Fifth Australasian Computer Science Conference
CityMelbourne, Australia
Period28/01/021/02/02

Keywords

  • Computer Software

Fingerprint

Dive into the research topics of 'Bracket Capabilities for Distributed Systems Security'. Together they form a unique fingerprint.

Cite this