Access and use control using externally controlled reference monitors
Author(s) -
Stephen D. Wolthusen
Publication year - 2002
Publication title -
acm sigops operating systems review
Language(s) - English
Resource type - Journals
SCImago Journal Rank - 0.18
H-Index - 104
eISSN - 1943-586X
pISSN - 0163-5980
DOI - 10.1145/844166.844170
Subject(s) - computer science , control (management) , distributed computing , operating system , real time computing , artificial intelligence
This paper presents a mechanism for the consistent enforcement of security policies within a distributed system by extending the reference monitor concept in such a way that both a conceptual and actual separation of the specification and enforcement of security policies by the reference monitor, hence an externally controlled reference monitor, is obtained. An externally controlled reference monitor may enforce multiple policies simultaneously; for this multiple external reference monitors can be queried. To maintain the policy independence of the reference monitor, subjects, objects, and operations are modeled in a formal theory which can also be mapped to multiple operating systems providing a operating system-independent mechanism for specifying and enforcing policies. This policy mechanism is briefly discussed, as is an example of an interpretation element and the corresponding implementation techniques for retrofitting the externally controlled reference monitor onto existing operating systems
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom