2007
DOI: 10.1007/s10207-007-0047-5
|View full text |Cite
|
Sign up to set email alerts
|

Discretionary capability confinement

Abstract: Abstract. Motivated by the need of application-level access control in dynamically extensible systems, this work proposes a static annotation system for modeling capabilies in a Java-like programming language. Unlike previous language-based capability systems, the proposed annotation system can provably enforce capability confinement. This confinement guarantee is leveraged to model a strong form of separation of duty known as hereditary mutual suspicion. The annotation system has been fully implemented in a s… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
8
0

Year Published

2010
2010
2024
2024

Publication Types

Select...
2
1

Relationship

0
3

Authors

Journals

citations
Cited by 3 publications
(8 citation statements)
references
References 39 publications
0
8
0
Order By: Relevance
“…Fig. 5 enumerates the type constraints of DCC as specified in [12]. We have successfully encoded all the DCC type constraints by an ISOMOD policy, which is displayed in Appendix A.…”
Section: Figure 5 DCC Type Constraintsmentioning
confidence: 99%
See 4 more Smart Citations
“…Fig. 5 enumerates the type constraints of DCC as specified in [12]. We have successfully encoded all the DCC type constraints by an ISOMOD policy, which is displayed in Appendix A.…”
Section: Figure 5 DCC Type Constraintsmentioning
confidence: 99%
“…We demonstrate how ISOMOD can be used for enforcing a general-purpose capability type system, Discretionary Capability Confinement (DCC) [12]. A lightweight, statically enforceable type system, DCC supports the use of abstractly-typed object references as capabilities in a Javalike object-oriented programming language.…”
Section: Discretionary Capability Confinementmentioning
confidence: 99%
See 3 more Smart Citations