• DocumentCode
    2217408
  • Title

    Access control for a modular, extensible storage service

  • Author

    Bacon, Jean ; Hayton, Richard ; Lo, Sai Lai ; Moody, Ken

  • Author_Institution
    Comput. Lab., Cambridge Univ., UK
  • fYear
    1994
  • fDate
    27-28 Jun 1994
  • Firstpage
    108
  • Lastpage
    114
  • Abstract
    We have designed and built a modular and extensible multi service storage architecture (MSSA) which allows evolution from, and compatibility with, traditional applications. The MSSA comprises a two-level hierarchy of storage servers with value-adding service layers above them. We present the access control mechanism of the MSSA. Access control lists (ACLs) are used to allow fine grained expression of policy together with capabilities for efficient runtime access after a once-off ACL check. Our capabilities are principal-specific and transient and their design ensures that access to objects is via the correct service hierarchy; for example, a directory object may only be manipulated via a directory service. The implementation of this protection is stateless at the servers above the storage service. The scheme also provides a convenient means to delegate rights for an object, temporarily, to an unprivileged server, for example a print-server. The fact that our capabilities are short-lived alleviates the requirement for selective revocation and crash recovery. We report on experiences with a prototype implementation of the scheme and suggest some optimisations
  • Keywords
    access control; file servers; memory architecture; multimedia systems; storage management; MSSA; access control lists; access control mechanism; crash recovery; extensible multi service storage architecture; fine grained expression; modular extensible storage service; once-off ACL check; principal-specific; print-server; prototype implementation; runtime access; selective revocation; service hierarchy; storage servers; two-level hierarchy; unprivileged server; value-adding service layers; Access control; Application software; Auditory displays; Authentication; Authorization; Computer architecture; File servers; Laboratories; Protection; Prototypes;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Distributed and Networked Environments, 1994. Proceedings., First International Workshop on Services in
  • Conference_Location
    Prague
  • Print_ISBN
    0-8186-5835-5
  • Type

    conf

  • DOI
    10.1109/SDNE.1994.337771
  • Filename
    337771