Complex Subjects, or: The Striving for Complexity is Ruling our World

Dirk Jonscher, Jonathan Moffett, Klaus R. Dittrich · 1993

In the course of the emergence of more complicated data models, which are used in the database world, more elaborate access control schemes are required as well. Security models have to be developed that are at least at the same level of abstraction as the data they have to deal with and the policies they have to enforce. We describe a role-based authorisation scheme for object-oriented data models which makes heavy use of implicit authorisations and which includes a domain concept. However, the main contribution of this paper is not to explain yet another access control scheme for such kinds of data models (there are already enough), but to discuss some mechanisms which allow the number of explicit access rights to be reduced as much as is meaningful by means of implicit authorisations, composite subjects and negative authorisations. Since negative authorisations (or prohibitions) are a bone of contention within the security community, we discuss some alternatives to avoid them witho...

Read the paper · More papers on PaperTik