Delegation through access control programs

Marvin M. Theimer, David Andrew Nichols, Doug Terry · 2003

Access control programs (ACPs), which permit controlled delegation of access rights to untrusted computer hosts, are discussed. Existing delegation protocols for distributed systems provide a way for a client to transfer its access rights to an intermediary, but provide only limited facilities for restricting the rights granted to the intermediary. ACPs are small programs that encode arbitrary specifications of delegated access rights. They are created and digitally signed by a client and passed to a server through an intermediary. When processing a request from the intermediary, the server executes the access control program to decide whether or not to grant the intermediary's request. Examples of ACPs used in a variety of applications are presented. A sample implementation of ACPs in the Andrew File System is described.>

Read the paper · More papers on PaperTik