In a distributed environment where users and resources are dispersed, security policies often require a more complex control mechanism, for access authorization. Authorization for a subject accessing objects depends not only on its normal access rights but also on its access history and interaction with other subjects. In this paper, frequently desirable multilevel exceptions are systematically categorized and it is shown that many state-dependent security policies are actually examples of these multilevel exceptions. An effective access control model based on Boolean expressions of classified categories is proposed to enforce all the multilevel exceptions in a uniform and elegant way
Published in:
Distributed Computing Systems, 1995., Proceedings of the Fifth IEEE Computer Society Workshop on Future Trends of
Date of Conference: 28-30 Aug 1995