2002 · 11 citations · 9 references
Authentication AuthorizationEngineeringInformation SecurityFormal VerificationPartial OrderLogical Access ControlAccess MethodAccess ControlTowards Access ControlData ManagementLogical Document StructuresData PrivacyComputer ScienceData SecurityCryptographyAutomated ReasoningFormal MethodsStructured DocumentAuthentication Access ControlComputer Security Model
This paper presents a first step towards a security model that defines access control for logical document structures. This model benefits from roles to abstract from users and from security levels (classifications) that abstract from objects. The security levels are defined on top of a complex document structure which will be needed for real web applications. Since a user clearance for an operation can be designated from roles and permissions, we use a lattice that defines a partial order over classifications to make an authorisation decision. Ordinary users should be able to handle the right management of their documents. The proposed model can be used in a decentral way.
9
Role-based access control models
Ravi Sandhu, Edward J. Coyne, H.L. Feinstein et al. · Computer · 1996 · 5.8K citations
A lattice model of secure information flow
Dorothy E. Denning · Communications of the ACM · 1976 · 1.9K citations · Full text
Steve DeRose, David Orchard · 2001 · 165 citations
PICS: Internet access controls without censorship
Paul Resnick, James Miller · Communications of the ACM · 1996 · 157 citations · Full text
Cascading Style Sheets, level 1
Steven Pemberton, not Cwi, H.W. Lie et al. · Data Archiving and Networked Services (DANS) · 2008 · 82 citations · Full text
Architectural Design, Model Synthesis, Document Engineering +5