Abstract
The per-method access control lists of standard internet technologies allow only simple forms of access control to be expressed and enforced. They also fail to enforce a strict need-to-know view of persistent data. Real applications require more flexible security constraints including parameter restrictions, logging of accesses and state-dependent access constraints. In particular, the concept of parameterised roles, central to a fine-grained specification of access rules and compliance with privacy laws, should be supported in a natural way. In this paper we demonstrate how an object-based approach using the mechanism of bracket capabilities can be used to enforce various kinds of access constraints including discretionary, mandatory and parameterised role-based access control. We give examples from a health information system incorporating secure patient access and secure access by appropriate medical and administrative personnel.
| Original language | English |
|---|---|
| Title of host publication | Proceedings of the 36th Annual Hawaii International Conference on System Sciences |
| Editors | R H Sprague Jr |
| Place of Publication | Los Alamitos, United States of America |
| Publisher | Institute of Electrical and Electronics Engineers (IEEE) |
| Pages | 1-9 |
| ISBN (Print) | 0769518745 |
| DOIs | |
| Publication status | Published - 2003 |
| Event | HICSS-36 (2003): 36th Annual Hawaii International Conference on System Sciences - Waikoloa, United States of America Duration: 6 Jan 2003 → 9 Jan 2003 |
Conference
| Conference | HICSS-36 (2003): 36th Annual Hawaii International Conference on System Sciences |
|---|---|
| City | Waikoloa, United States of America |
| Period | 6/01/03 → 9/01/03 |
Keywords
- Data Format
Fingerprint
Dive into the research topics of 'Supporting Parameterised Roles with Object-based Access Control'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver