• DocumentCode
    2576139
  • Title

    Beyond the pale of MAC and DAC-defining new forms of access control

  • Author

    McCollum, Catherine Jensen ; Messing, Judith R. ; Notargiacomo, LouAnna

  • Author_Institution
    Unisys Defense Syst., McLean, VA, USA
  • fYear
    1990
  • fDate
    7-9 May 1990
  • Firstpage
    190
  • Lastpage
    200
  • Abstract
    Examples of DoD/intelligence data protection requirements are described that cannot be handled through traditional mandatory (MAC) or discretionary (DAC) access controls, and two new forms of access controls to respond to these problems are proposed. First, a user attribute-based access control for enforcement of dissemination controls is introduced. Second, a type of access control known as owner-retained access control is described, to provide a privilege-based form of access control that, unlike DAC, prevents access to data being extended to others without the owner´s concurrence. For both types of controls, the access control rules to be enforced and the implications of providing automated enforcement of these controls are discussed. The two forms of control are compared, and an informal model is presented that provides a common framework for representing both. In conclusion, the benefits and drawbacks of this approach are discussed, and some areas for future work are identified
  • Keywords
    military computing; security of data; DAC; DoD/intelligence data protection requirements; MAC; automated enforcement; discretionary access control; dissemination controls; informal model; mandatory access control; owner´s concurrence; owner-retained access control; privilege-based form; user attribute-based access control; Access control; Automatic control; Computer security; Control systems; History; Intelligent systems; Lattices; Mathematical model; Protection; Research and development;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Research in Security and Privacy, 1990. Proceedings., 1990 IEEE Computer Society Symposium on
  • Conference_Location
    Oakland, CA
  • Print_ISBN
    0-8186-2060-9
  • Type

    conf

  • DOI
    10.1109/RISP.1990.63850
  • Filename
    63850