On the minimality of testing for rights in transformation models
Ravi S. Sandhu, Srinivas Ganta · 2002
Defines and analyzes a family of access control models, called transformation models, which are based on the concept of transformation of rights. In these models, propagation of access rights is authorized entirely by existing rights for the object in question. Transformation models are useful for expressing various kinds of consistency, confidentiality, and integrity controls. These models also generalize the monotonic transform model of Sandhu, and its non-monotonic extension (NMT) by Sandhu and Suri. The authors argue that NMT is inadequate for expressing the document release example discussed by Sandhu and Suri, because it can test only one access matrix cell in its state changing commands. They then analyze the relative expressive power of testing two access matrix cells in state changing commands versus testing more than two. The conclusion is that it suffices to allow testing for two cells.>