DocumentCode :
1822883
Title :
Delegation of obligations
Author :
Schaad, Andreas ; Moffett, Jonathan D.
Author_Institution :
Dept. of Comput. Sci., York Univ., UK
fYear :
2002
fDate :
2002
Firstpage :
25
Lastpage :
35
Abstract :
Obligation policies are one main means of exercising control within an organisation. They specify the actions that some subject has to perform. The authority over these actions needs to be specified in authorisation policies. Current policy notations provide us with the needed structure to represent authorisations and obligations as policy objects for distributed systems management. They support the delegation of authorisations but not of obligations, yet there is a strong relationship between the two policy types, and the delegation of obligations needs to be supported as well, requiring the introduction of a new type of policy which we call a "review". This paper investigates the general principles underlying the delegation of policy objects, putting specific emphasis on the delegation of obligations. The Alloy specification language is used to specify and illustrate these principles. The main issues that are discussed are: the balance between authorisation and obligation policies; the source of obligations and reasons for their delegation; and the need for review policies to help control the delegation of obligations
Keywords :
DP management; authorisation; distributed processing; formal specification; specification languages; Alloy specification language; action authority specification; authorisation delegation; authorisation policies; distributed systems management; obligation delegation; obligation policies; obligation source; policy object delegation; review policies; Authorization; Electrical capacitance tomography; Hip; Identity management systems; Permission; Specification languages;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Policies for Distributed Systems and Networks, 2002. Proceedings. Third International Workshop on
Conference_Location :
Monterey, CA
Print_ISBN :
0-7695-1611-4
Type :
conf
DOI :
10.1109/POLICY.2002.1011290
Filename :
1011290
Link To Document :
بازگشت