| Martn Abadi, Michael Burrows, Butler Lampson, and Gordon Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, October 1993. |
....One way in which it may seem that our language is restricted is that we we do not provide explicit support for groups and roles. Many policy languages talk about groups, where a group is a set of subjects such that if a group has a property, then every member of the group has the property (cf. [1, 23]) In role based access control models [27, 36, 15, 20] roles are an intermediary between individuals and rights. More specifically, an individual obtains a right by assuming a role that is associated with that right. For example, Alice may need to assume the role of Department Chair in order to ....
....as Dept. Chair(Alice) Permitted(Alice, sign the budget) The fact Dept. Chair(Alice) would be added to the environment when Alice assumes the role and would be removed when she relinquishes it. Alternatively, we could add a sort Roles to our logic along with the predicate As (as suggested in [1]) where As(e, r) means that entity e is acting as role r (in other words, e has assumed role r) Continuing our example, Alice, acting as the Department Chair, may sign the budget could be written in the logic as As(Alice, Dept. Chair) Permitted(Alice, sign the budget) The second encoding ....
M. Abadi, M. Burrows, B. Lampson, and G. D. Plotkin. A calculus for access control in distributed systems. ACM Trans. Prog. Lang. Syst., 15(4):706--734, 1993.
....approach is desirable to help establish authorization policies and remove conflicts in the policies before they are integrated with other system functionalities. Currently there exist various models [9, 7, 5, 25, 12, 18, 19] explaining security properties and approaches dealing with delegations [1, 6, 15] and conflicts [14, 4] We argue that an engineering approach based on software engineering technologies can be developed to assist users and designers in better implementing the models and applying the available approaches. 2 AUTHORIZATION POLICY ENGINEERING Authorization policies in computer ....
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin, "A calculus for access control in distributed systems," ACM Transactions on Programming Languages and Systems, 15(4): 706-734, Oct. 1993
.... intelligence research as bases for defeasible reasoning [Shv90] logics of agents [RG93] and logics of authentication [BAN90, Mat97] Monniaux [Mon01] shows that BAN and GNY logics are decidable, while Massacci [Mas97] gives a tableaux calculus for the (undecidable) logic of access control of [ABLP93]. We refer the reader to [Mon01] for more information on such logics. Multi modal logics like Propositional Dynamic Logic [Gol87] have also been used to model the changing states of a program. Finally, propositional bi modal tense logics give a very simple and elegant model of the flow of time ....
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems 15(4):706--734, 1993.
....because it is too long to fit in a short paper. It can also be di#cult to extend operational semantics to additional language features in a modular way. Wallach, Appel and Felten [5] model the mechanism with an operational semantics that manipulates formulas in a formal logic of authentication [1]. They show that the particular logical deductions corresponding to checkPermission can be decided e#ciently, and propose an implementation called security passing style in which the security state is calculated in advance. The only result proven is equivalence of the two implementations. They ....
M. Abadi, M. Burrows, B. Lampson and G. Plotkin. A calculus for access control in distributed systems. ACM Trans. Programming Languages and Systems 15 (4), 1993.
....authentication is complicated by the fact that a request may originate from a distant host and traverse multiple machines and network channels that are not trusted. Abadi, Burrows, Lampson, Plotkin, Wobber, et al. developed a logic for authentication and access control in distributed systems [1, 48]. They also designed and implemented a security system based on this logic. The basic concepts of SRC logic are principals and statements. Principals make statements. A says S means that principal A makes the statement S (an assertion or a request) There is a speak for relation among ....
....conjunctions of principals; however, doing this requires an exponential number of delegations in the worst case. Fourth, there is no re delegation control mechanism; every delegation can be freely re delegated. Even with the above limitations, validity in SRC logic is undecidable in general. In [1], Abadi et al. defined two simplified classes of access control problems that are decidable. One class is worst case exponential time solvable. The other class is the result of even further simplification and is computationally tractable. 18 2.5 Trust Management Authorization in Internet ....
[Article contains additional citation context not shown here]
Martn Abadi, Michael Burrows, Butler Lampson, and Gordon Plotkin, "A Calculus for Access Control in Distributed Systems," ACM Transactions on Programming Languages and Systems, 15:4, pp. 706--734, October 1993. Also available as SRC Research Report 70.
....networks as graphs and make access control decisions by finding paths in the graphs. An alternative approach could be to define a logical language for describing delegation and to make decisions by proving theorems of the logic. It appears that the access control calculus of Abadi et al. [1, 6, 10] could be adapted for the purpose. However, the calculus was developed before key based systems and it does not directly support anonymous keys in the certificate chain. The three most prominent proposals for distributed trust management on open communications networks are SPKI certificates [5] ....
Martn Abadi, Michael Burrows, Butler Lampson, and Gordon Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, September 1993.
....implementation and analyse appropriate protocols. The ideas expressed in [8] lie at a different level from ours, as the focus there is exclusively on access control. The theoretical work can be broadly divided in two main streams: logics, where the trust engine is responsible for constructing [5, 4, 12 14] or checking [1] a proof that the desired request is valid; and computational models [21, 7] like our approach. Burrows et al. propose the BAN logic [5] a language for expressing properties of and reasoning about the authentication process between two entities. The language is founded on ....
....expressing properties of and reasoning about the authentication process between two entities. The language is founded on cryptographic reasoning with logical operators dealing with notions of shared keys, public keys, encrypted statements, secrets, nonce freshness and statement jurisdiction. In [4], Abadi et al. enhance the language by introducing delegation and groups of principals: each principal can have a particular role in particular actions. The Authorisation Specification Language (ASL) by Jajodia et al. 12] separates explicitly policies and basic mechanisms, so as to allow a more ....
Michael Burrows, Martn Abadi, Butler W. Lampson, and Gordon Plotkin. A calculus for access control in distributed systems. LNCS, 576:1--23, 1991.
....contrast our system with other research in this area with reference to flexibility in representation of policies and delegations, types of delegations, delegation management schemes and delegation protocols. A logical approach for authentication, access control and trust is defined by Abadi et al. [1, 10], that focuses on delegation as a representation of the speaks for relation. The system is based on a formal semantics that explains how delegations interact with various combination operators for principals. However, delegations are unconstrained, i.e. a delegation gives the delegatee the right ....
Martn Abadi, Michael Burrows, Butler Lampson, and Gordon Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, September 1993.
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, 1993.
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, 1993.
No context found.
Mart n Abadi, Michael Burrows, Butler Lampson, and Gordon Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, October 1993.
No context found.
Martn Abadi, Michael Burrows, Butler Lampson, and Gordon Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, October 1993.
No context found.
Martn Abadi, Michael Burrows, Butler Lampson, and Gordon D. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, September 1993.
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, Oct. 1993.
No context found.
Abadi, Burrows, Lampson and Plotkin, "A Calculus for Access Control in Distributed Systems", DEC SRC-070, revised August 28, 1991.
No context found.
Abadi, M., Burrows, M., Lampson, B., and Plotkin, G. 1993. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems 15, 4 (September), 706-734.
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15:706-734, 1993.
No context found.
3 M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15:706-734, 1993.
No context found.
M. Abadi, M. Burrow, B. Lampson, and G. Plotkin. A Calculus for Access Control in Distributed Systems. Technical Report 70, DEC, System Research Center, Palo Alto, February 1991.
No context found.
M. Abadi, M. Burrow, B. Lampson, and G. Plotkin. A Calculus for Access Control in Distributed Systems. Technical Report 70, DEC, System Research Center, Palo Alto, February 1991.
No context found.
Martn Abadi, Michael Burrows, Butler Lampson, and Gordon Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, October 1993.
No context found.
Abadi, M., Burrows, M., Lampson, B.: A Calculus for Access Control in Distributed Systems. ACM Transactions on Programming Languages and Systems 15(4) (1993) 706--734
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, Oct. 1993.
No context found.
Martn Abadi, Michael Burrows, Butler Lampson, and Gordon Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, October 1993.
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, September 1993. 3
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, September 1993. 4
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. D. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, September 1993.
No context found.
Abadi, M., Burrows, M., Lampson, B., Plotkin, G.: A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems 15 (1993) 1--29 1
No context found.
Martin Abadi, Michael Burrows, Butler Lampson, and Gordon D. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, September 1993.
No context found.
M. Burrows, M. Abadi, B. W. Lampson, and G. Plotkin. A calculus for access control in distributed systems. LNCS, 576:1--23, 1991.
No context found.
M. Burrows, M. Abadi, B. W. Lampson, and G. Plotkin. A calculus for access control in distributed systems. In Proc. of 11th Annual International Cryptology Conference Advances in Cryptology (CRYPTO '91), volume 576, pages 1--23, 1991.
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. D. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, September 1993.
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. TOPLAS, 15(4):706--734, Sept. 1993.
No context found.
Mart n Abadi, Michael Burrows, Butler Lampson, and Gordon Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, October 1993.
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 4(15):706-734, Sept. 1993.
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. D. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, Sept. 1993. 5, 11
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 4(15):706--734, Sept. 1993.
No context found.
Martn Abadi, Michael Burrows, Butler Lampson, and Gordon D. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, September 1993.
No context found.
Martn Abadi, Michael Burrows, Butler Lampson, and Gordon Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, October 1993.
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706-- 734, September 1993.
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 4(15):706-734, Sept. 1993.
No context found.
M. Burrows, M. Abadi, B. W. Lampson, and G. Plotkin. A calculus for access control in distributed systems. LNCS, 576:1--23, 1991.
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, September 1993.
No context found.
M. Abadi, M. Burrows, B. W. Lampson, and G. D. Plotkin. A calculus for access control in distributed systems. Transactions on Programming Languages and Systems, 15(4):706--734, Sept. 1993. 17
No context found.
Mart n Abadi, Michael Burrows, Butler Lampson, and Gordon Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, October 1993.
No context found.
M. Abadi, M. Burrows, B. W. Lampson, and G. D. Plotkin. A calculus for access control in distributed systems. Transactions on Programming Languages and Systems, 15(4):706--734, Sept. 1993.
No context found.
Mart n Abadi, Michael Burrows, Butler Lampson, and Gordon Plotkin. A calculus for access control in distributed systems. ACM Transactions on Programming Languages and Systems, 15(4):706--734, September 1993.
No context found.
M. Burrows, M. Abadi, B. W. Lampson, and G. Plotkin. A calculus for access control in distributed systems. LNCS, 576:1--23, 1991.
No context found.
M. Abadi, M. Burrows, B. Lampson, and G. Plotkin, "A calculus for access control in distributed systems," ACM Transactions on Programming Languages and Systems, vol. 15, pp. 706--734, Sept. 1993.
No context found.
Abadi, Burrows, Lampson and Plotkin, "A Calculus for Access Control in Distributed Systems", DEC SRC-070, revised August 28, 1991.
First 50 documents Next 50
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC