pith. sign in

arxiv: cs/0604081 · v1 · pith:VIHWWAM5new · submitted 2006-04-21 · 💻 cs.LO · cs.CR

Event Systems and Access Control

classification 💻 cs.LO cs.CR
keywords accesscontrolrightssystemsusereventconsiderobligations
0
0 comments X
read the original abstract

We consider the interpretations of notions of access control (permissions, interdictions, obligations, and user rights) as run-time properties of information systems specified as event systems with fairness. We give proof rules for verifying that an access control policy is enforced in a system, and consider preservation of access control by refinement of event systems. In particular, refinement of user rights is non-trivial; we propose to combine low-level user rights and system obligations to implement high-level user rights.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.