Languages for Specifying Protection Requirements in Data Base Systems. Part I,
Abstract
This report develops a macro-oriented model of access control to accommodate constructs of protection languages at many levels of sophistication. The concept of ownership is explicitly represented in the model and is expanded to include subownership and conditional ownership. The basic sets of the set-theoretic model are presented and the set of system states is derived from the set of all values of the resources. Restrictions on resource values define subsets of states, which are described by expressions called conditions. The concept of a five-dimensional security space is used to visualize how authorization specifications and access requests are manipulated by the authorization and enforcement processes. Several examples are presented to illustrate the relationships among the various parts of the security space.
Document Details
- Document Type
- Technical Report
- Publication Date
- Jan 01, 1975
- Accession Number
- ADA006280
Entities
People
- D. K. Hsiao
- H. R. Hartson
Organizations
- Ohio State University