Proceedings of the 1999 IEEE Symposium on Security and Privacy (Cat. No.99CB36344)
DOI: 10.1109/secpri.1999.766718
|View full text |Cite
|
Sign up to set email alerts
|

A user-centered, modular authorization service built on an RBAC foundation

Abstract: Psychological acceptability has been mentioned as a requirement for secure systems for as long as least privilege and fail safe defaults, but until now has been all but ignored in the actual design of secure systems. We place this principle at the center of our design for Adage, an authorization service for distributed applications. We employ usability design techniques to specify and test the features of our authorization language and the corresponding administrative GUI. Our testing results reinforce our ini… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
40
0

Publication Types

Select...
6
3
1

Relationship

0
10

Authors

Journals

citations
Cited by 61 publications
(40 citation statements)
references
References 27 publications
0
40
0
Order By: Relevance
“…This means, even if delegations are revoked, the Delegation objects and the corresponding links are not deleted. If our metamodel for role-based delegation is used as a basis for the implementation of an authorization engine [27,35], this information can be used for an audit trail.…”
Section: Revocationconstraintam: Can Revokegdstrongcasc(accountingmanmentioning
confidence: 99%
“…This means, even if delegations are revoked, the Delegation objects and the corresponding links are not deleted. If our metamodel for role-based delegation is used as a basis for the implementation of an authorization engine [27,35], this information can be used for an audit trail.…”
Section: Revocationconstraintam: Can Revokegdstrongcasc(accountingmanmentioning
confidence: 99%
“…These include the following. Zurko et al [29] have included a graphical user interface for access control policy authoring with their Adage system. The HP Select Access Policy Builder [19] includes a grid-like user interface.…”
Section: Related Workmentioning
confidence: 99%
“…One of those engines is Adage, developed by Zurko et al [30]. Adage has been developed with similar goals in mind.…”
Section: Related Workmentioning
confidence: 99%